# Dell Fixes Multiple Critical Flaws in Container Storage Modules
Dell has shipped security updates for a set of critical vulnerabilities in Dell Container Storage Modules (CSM), several of them scoring the maximum severity, that could let attackers seize control of affected systems. The fixes are published in the advisory DSA-2026-448.
CSM adds storage capabilities to Kubernetes clusters, which makes these modules a high value target. They sit close to sensitive data and, if compromised, can serve as a foothold for moving deeper into a cluster.
## The vulnerabilities
**CVE-2026-63688 (CVSS 10.0)** is a missing authentication flaw in the csm-authorization-storage gRPC server. An unauthenticated remote attacker can reach it and pull storage backend administrator credentials for every registered storage array. Dell describes this as a full break of the csm-authorization security model, handing an attacker administrative control over storage infrastructure across all five supported Dell storage product families.
**CVE-2026-63692 (CVSS 10.0)** is a second missing authentication flaw, this time in the authorization proxy and tenant service. An unauthenticated attacker on the network can skip the authentication controls entirely and obtain administrative privileges. Per Dell, that means complete control over the authorization service and the ability to read or alter storage resources belonging to any tenant.
**CVE-2026-67269 (CVSS 9.9)** is an improper privilege management flaw in the ContainerStorageModule custom resource reconciler. A low privilege remote attacker can escalate to root on cluster nodes, and Dell warns that a single crafted custom resource submission is enough to compromise every node in the Kubernetes cluster.
**CVE-2026-54472 (CVSS 9.8)** is a hard-coded credentials flaw in the CSM Authorization module. An unauthenticated remote attacker can forge cryptographically valid administrative tokens and walk into the CSM Authorization proxy, which opens the door to managing storage access policies across all connected tenants.
**CVE-2026-61421 (CVSS 9.8)** is a hard-coded cryptographic key flaw in the JWT authentication component of karavi-authorization. Because the signing secret is publicly available, any unauthenticated attacker who knows it can mint valid authentication tokens and gain administrative privileges.
**CVE-2026-67273 (CVSS 9.6)** is a template engine injection flaw. A low privilege attacker with remote access can escalate privileges, read sensitive data, and tamper with RBAC. Dell notes that successful exploitation grants cluster-wide read access to Kubernetes Secrets plus the ability to create cluster-scoped RBAC resources, which effectively defeats the intended Kubernetes access controls.
## Affected versions and the fix
Every CSM release before **1.17.0** is affected. The flaws are resolved in **1.18.0**.
There are no workarounds and no mitigations. Updating to the latest version is the only route to protection. Dell also advises customers to rotate any JWT signing secrets after patching, since the hard-coded key and credential issues mean previously issued tokens can no longer be trusted.
## Why this matters
Dell products have drawn active exploitation before, including CVE-2021-21551 and the Dell RecoverPoint for VMs zero-day CVE-2026-22769. Given that track record and the maximum severity of the top flaws here, applying 1.18.0 promptly is the sensible move for anyone running CSM.