Dell has fixed six critical security vulnerabilities in its Container Storage Modules (CSM), which are used to connect enterprise storage systems to Kubernetes environments . The vulnerabilities could, under certain circumstances, allow unauthorized remote attackers to bypass access control mechanisms and gain elevated administrative privileges on critical infrastructure.

The company urges its customers to proceed with the necessary updates, as the issues affect functions related to authentication, authorization and access to storage resources. In environments where many applications and services are running, a successful attack could have consequences beyond a single system, affecting different users and applications sharing the same infrastructure.
Dell Container Storage Modules in the spotlight
Dell CSM is a set of tools that extend the capabilities of the Kubernetes Container Storage Interface (CSI), enabling applications running in containers to use enterprise storage infrastructures.
The technology supports key Dell product lines, including PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT, enabling organizations to connect their applications to storage resources and manage data in complex cloud-native environments.
See also: FortiMail: Active exploitation of CVE-2026-104286
However, this architecture makes authentication and authorization mechanisms particularly important. If an attacker manages to bypass these controls, they may gain access to resources normally reserved for administrators or authorized services.
According to Dell's security update, the two key vulnerabilities are located in the Dell CSM Authorization and are linked to the absence of sufficient authentication checks for critical functions.
CVE-2026-63688: Access to administrator credentials
The first vulnerability, identified as CVE-2026-63688, concerns a weakness that could allow unauthorized remote attackers to gain access to the administrator credentials of connected backend storage systems.
If the exploit is successful, attackers can bypass the authorization process and gain full administrative control of the storage infrastructure. Such an incident could compromise the confidentiality and integrity of data, as well as the availability of critical enterprise applications.
For an organization that relies on centralized storage systems, losing control of administrative credentials can have a ripple effect. Depending on the privileges an attacker gains and the configuration of the infrastructure, they could attempt unauthorized access, data corruption , or service disruption.

CVE-2026-63692: Authorization Bypass
The second critical flaw, CVE-2026-63692, is found in the authorization proxy and tenant service of Dell CSM.
According to the company, the vulnerability could allow malicious users to bypass authentication checks and gain administrator privileges on the authorization service.
See also: Cisco Catalyst SD-WAN Manager: Critical vulnerability in the KEV Catalog
Dell warns that this vulnerability could lead to unauthorized access and modification of storage resources belonging to different tenants, i.e. distinct environments or groups of users sharing the same infrastructure.
This is particularly important for enterprises using multi-tenant architectures, as the isolation of rights between different applications and users is a key prerequisite for secure operation.
Four more critical vulnerabilities
In addition to the two issues above, Dell announced fixes for four more critical vulnerabilities in CSMs. Their impacts include:
- CVE-2026-67269: Possibility of obtaining root privileges on cluster nodes by remote attackers, even without prior privileges.
- CVE-2026-54472: Possibility of gaining administrative access to the CSM authorization proxy.
- CVE-2026-61421: Possibility of forging authentication tokens, with the aim of obtaining administrator rights.
- CVE-2026-67273: Kubernetes access control bypass, which could allow cluster-wide reading of Kubernetes Secrets.
Kubernetes Secrets are used to store sensitive information, such as credentials, keys, and tokens that applications need to communicate with other services. If such data is exposed, an attacker may gain additional access capabilities, depending on their content and the permissions they grant.
The combined presence of vulnerabilities at different levels of the infrastructure highlights why organizations must consider the security of their systems as a whole and not just individual software components.

How can businesses be protected?
Dell recommends upgrading Container Storage Modules to version 1.18.0 or later, which includes the relevant security fixes.
Administrators should check which versions are being used, confirm that fixes have been applied to all relevant environments, and follow Dell's official upgrade guidelines. Before making any changes to production systems, it is advisable to assess compatibility and have a recovery plan in place in case of an issue.
See also: CVE-2026-86950: PoC for critical Apple CoreGraphics vulnerability
At the same time, it is recommended to check access permissions, service exposure to untrusted networks, and activity in management mechanisms. Monitoring unusual authorization requests, suspicious access to storage resources, and unexpected changes to Kubernetes Secrets can help identify signs of a breach.
Dell has not identified these vulnerabilities as being actively exploited in the information described in the advisory. However, the absence of a confirmed exploit does not mean that organizations can postpone installing the updates.
Previous attacks on Dell systems
The incident is part of a broader history of Dell vulnerabilities being exploited in real-world attacks. The North Korean Lazarus, for example, exploited the CVE-2021-21551 in Dell's dbutil driver, installing rootkits on victim systems.
Additionally, Mandiant and Google Threat Intelligence Group have linked the UNC6201 to the exploitation of the CVE-2026-22769 in Dell RecoverPoint for Virtual Machines. The activity reportedly began at least in mid-2024 and involved malware and hidden network interfaces on VMware ESXi servers.
The case highlights that storage and virtualization infrastructures are attractive targets because they are often at the center of an organization's operations.
For businesses using Dell CSM and Kubernetes, it is a priority to immediately apply fixes and verify the security of credentials and access rights. Protecting these systems is not only about preventing a potential breach, but also maintaining the availability and reliability of critical corporate data.
source: www.bleepingcomputer.com
