Administrative Bypass in Dell CSM: Six Vulnerabilities Expose Storage Backend Credentials

Posted

Administrative Bypass in Dell CSM

Six vulnerabilities in Dell Container Storage Modules (CSM) allow for the bypass of the csm-authorization security model. According to the Dell security update, these flaws provide unauthenticated access to storage infrastructure across PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT product families. The affected versions include all releases prior to 1.17.0.

Technical Mechanics of the Vulnerabilities

The severity of this disclosure is driven by two CVSS 10.0 vulnerabilities. CVE-2026-63688 involves missing authentication in the csm-authorization-storage gRPC server, which allows remote attackers to retrieve administrator credentials for registered storage arrays. CVE-2026-63692 similarly involves missing authentication, this time within the authorization proxy and tenant service, permitting unauthenticated network attackers to gain administrative privileges.

Companion Authentication Failures

The vulnerability set includes additional flaws that facilitate token forgery and privilege escalation. CVE-2026-54472 stems from hard-coded credentials in the CSM Authorization module, allowing for the creation of cryptographically valid administrative tokens. CVE-2026-61421 involves a hard-coded cryptographic key in the JWT authentication component of karavi-authorization, which allows attackers to forge authentication tokens using a publicly available signing secret.

Further escalation is possible through CVE-2026-67269, an improper privilege management flaw in the ContainerStorageModule Custom Resource reconciler that enables a low-privilege remote attacker to escalate to root on cluster nodes. Finally, CVE-2026-67273 describes an improper neutralization issue in the template engine, permitting low-privilege attackers to access Kubernetes Secrets cluster-wide and modify Role-Based Access Control (RBAC) configurations.

The Trust-Through-Defaults Pattern

These vulnerabilities align with the Agent Identity Layer Risk pattern. This occurs when systems are designed with permissive defaults that assume a secure, isolated environment, which are then left active in production. The core issue is a failure to verify the binding between a key and an identity, a recurring theme in recent infrastructure disclosures.

This pattern is not limited to storage. We previously documented this in the Loom CVE-2026-103956, where the orchestration layer featured a hard-coded fallback that granted super-admin access to unauthenticated users. In both the Loom and Dell CSM cases, the systems default to trust at the point where verification should be enforced.

Historical Context

While there is no confirmed active exploitation of these specific Dell vulnerabilities, historical data indicates that Dell infrastructure has been targeted previously. CVE-2021-21551 was utilized by the Lazarus group for rootkit deployment, and CVE-2026-22769 was used by the actor UNC6201 (Silk Typhoon) for malware deployment on ESXi servers. The latter incident resulted in a CISA directive requiring government agencies to patch within three days.

Remediation Requirements

The remediation path for these six CVEs is limited. Organizations must upgrade to version 1.18.0, as no workarounds or mitigations are available. Because the vulnerabilities involve hard-coded secrets and token forgery, rotating JWT signing secrets is a necessary step following the upgrade. Relying on network isolation as a primary security control is insufficient given the nature of these flaws.

Trust & Security