Skip to content

Security2 publishers2 min readPublished

Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array

Dell patched six critical flaws in its Kubernetes storage modules, one letting unauthenticated attackers pull admin credentials for every registered array. The Authorization module holds those keys for each array it fronts, so one reachable deployment exposes all the storage registered behind it.

The Watch · Security desk

Illustration accompanying Unauthenticated Dell CSM flaw leaks admin credentials for every registered storage array

What happened

  • A second maximum-severity flaw, CVE-2026-63692, sits in the Authorization proxy and tenant service and grants administrative privileges by bypassing authentication.
  • Four further critical CSM bugs fixed the same day give root on cluster nodes, proxy admin access, forged admin tokens and cluster-wide reads of Kubernetes Secrets.
  • The fixes ship in Container Storage Modules 1.18.0 and later, and Dell wrote that it "recommends customers to upgrade at the earliest opportunity."
  • Dell has not flagged any of the six flaws as actively exploited.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • cost Operators who ran a reachable pre-1.18.0 Authorization service face rotating administrator credentials on every registered array, since an upgrade does not invalidate a password already read.
  • decision The Kubernetes Secrets read and node-root bugs make the upgrade a job for the cluster platform team as well as the storage team.
  • constraint Tenant separation and Kubernetes access controls are the protections these bugs bypass, so neither buys time before the upgrade lands.

On exploitability, CVE-2026-63688 is the worst flaw in the release. It needs no account and works remotely [4]. The attacker gets the backend administrator credentials for every storage array registered with the Authorization module, plus full administrative control of the storage infrastructure [4]. Dell's Thursday advisory traces this flaw and CVE-2026-63692 to the same weakness: missing authentication for critical functions [3].

Registration sets the scope. CSM fronts Dell's PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT arrays and extends the standard Kubernetes CSI drivers [2]. A shop that registered arrays from several of those product lines with one Authorization deployment has put all of them behind the same unauthenticated function [4]. Dell described the tenant-service bug in multi-tenant terms. "This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants," the company said [6].

Including the companion bugs, the release fixes six critical flaws. The report describes every one as exploitable without prior credentials or privileges [1]. At least three of the six end in administrative control of the Authorization service, its proxy, or the storage behind it [2].

The report does not say whether exploit code is public, what network position an attacker needs, or whether any mitigation short of the upgrade exists. Reachability therefore sets each deployment's deadline. An Authorization proxy that answers from outside the cluster offers the full credential scope of CVE-2026-63688 to anyone on that network [4].

Dell's exploitation history comes from other products [10][11]. North Korea's Lazarus group used an insufficient-access-control bug in Dell's dbutil driver, CVE-2021-21551, to plant a Windows rootkit [10]. In February, Mandiant and the Google Threat Intelligence Group reported that UNC6201, a suspected Chinese state-backed group, had exploited a hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines, CVE-2026-22769, since at least mid-2024 [11]. The group used it to deploy malware and create hidden network interfaces on VMware ESXi servers [11]. The researchers found overlaps between UNC6201 and Silk Typhoon [12]. Days later, CISA ordered federal agencies to patch vulnerable Dell systems within three days [13].

What to watch

  • A Dell or CISA notice that any of the six CSM CVEs is being exploited; after the RecoverPoint disclosure, CISA gave agencies three days to patch.
  • Exploit code or a technical write-up for CVE-2026-63688 that settles what network access an attacker needs to reach the Authorization proxy.
  • Any Dell advisory update adding a workaround for clusters that cannot move to CSM 1.18.0 quickly.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories