
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.
CSM supports Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes.
In a security advisory published on Thursday, Dell said that both critical security flaws were found in the Dell CSM Authorization security module and stem from "missing authentication for critical functions" weaknesses.
The first (tracked as CVE-2026-63688) allows unauthenticated remote attackers to access storage backend administrator credentials for all registered storage arrays and bypass authorization to gain full administrative control over the storage infrastructure.
Successful exploitation of the second flaw (CVE-2026-63692), present in the authorization proxy and tenant service, also allows threat actors to gain admin privileges by bypassing authentication controls.
"This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants," Dell warned.
The same day, the company also patched four additional critical-severity Dell CSM security issues that remote attackers can also exploit without privileges to gain root on cluster nodes (CVE-2026-67269), gain administrative access to the CSM Authorization proxy (CVE-2026-54472), forge authentication tokens to gain administrative privileges (CVE-2026-61421), and bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets (CVE-2026-67273).
"Dell recommends customers to upgrade at the earliest opportunity," the company added, advising customers to update their container storage modules to version 1.18.0 or later, which patches these flaws.
Dell vulnerabilities exploited in the wild
While Dell has yet to flag these security issues as actively exploited, state-sponsored hackers have abused other Dell vulnerabilities in attacks in recent years.
For instance, the North Korean Lazarus hacking group deployed a Windows rootkit on victims' systems by exploiting an insufficient access control vulnerability (CVE-2021-21551) in the Dell dbutil driver.
More recently, in February, Mandiant and the Google Threat Intelligence Group (GTIG) revealed that a suspected Chinese state-backed hacking group (UNC6201) had been exploiting a maximum-severity hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to deploy malware payloads and create hidden network interfaces on VMware ESXi servers.
The security researchers also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, known for targeting government agencies with custom Spawnant and Zipline malware in Ivanti zero-day attacks.
Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch vulnerable Dell systems on their networks within three days.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.









English (US) ·