Close Menu
NCIJ Network NCIJ Network
    What's Hot

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 2, 2026

    Federal Judge Slams the Brakes on Big Bend Border Wall Construction

    October 2, 2026

    How Sea Cucumbers Drive Crime From China to Mexico

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • IMF Praises El Salvador But Tries To Scale Back Bitcoin Use
    • Federal Judge Slams the Brakes on Big Bend Border Wall Construction
    • How Sea Cucumbers Drive Crime From China to Mexico
    • Flydubai pilot recounts cockpit stabbing in call with Indian PM Modi | Aviation News
    • Bosses of three firms that supply trains to UK railways made £3.5m last year | Rail industry
    • iPhone 18 Pro Max stuck in SOS mode? Try AT&T’s urgent fix ASAP
    • Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
    • Trump’s possible next AI czar, Jay Clayton, helped pioneer the SEC’s crypto crackdown
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 2, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 02, 2026Vulnerability / Cloud Security

    Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems.

    The vulnerabilities are listed below –

    • CVE-2026-63688 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays.
    • CVE-2026-63692 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges.
    • CVE-2026-67269 (CVSS score: 9.9) – An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attacker could exploit to escalate privileges and gain root-level access on cluster nodes.
    • CVE-2026-54472 (CVSS score: 9.8) – A use of hard-coded credentials vulnerability in the CSM Authorization module that a remote unauthenticated attacker could exploit to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy.
    • CVE-2026-61421 (CVSS score: 9.8) – A use of hard-coded cryptographic key vulnerability in the JWT authentication component of karavi-authorization that a remote unauthenticated attacker with knowledge of this publicly available signing secret could exploit to forge authentication tokens and gain administrative privileges.
    • CVE-2026-67273 (CVSS score: 9.6) – An improper neutralization of special elements used in a template engine vulnerability that a low-privilege attacker with remote access could exploit to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering.

    “This vulnerability is considered critical as it enables a complete bypass of the csm-authorization security model, allowing an attacker to gain full administrative control over the storage infrastructure spanning all five supported Dell storage product families,” Dell said about CVE-2026-63688.

    Cybersecurity

    As for CVE-2026-63692, Dell noted that successful exploitation could enable an unauthenticated attacker to gain complete administrative control over the authorization service, and allow them to access or manipulate storage resources across all tenants.

    The PC maker also noted that an attacker can exploit CVE-2026-67269 to compromise all nodes in a Kubernetes cluster through a single custom resource submission. CVE-2026-54472, on the other hand, can be weaponized to sidestep authentication controls for the CSM Authorization proxy and enable unauthorized management of storage access policies across all connected tenants. Dell is recommending that customers apply the updates and rotate any JWT signing secrets.

    “Successful exploitation grants the attacker cluster-wide read access to Kubernetes Secrets and the ability to create cluster-scoped RBAC resources, effectively bypassing the intended Kubernetes access controls,” Dell said in its advisory for CVE-2026-67273.

    The flaws, which affect all versions of CSM prior to 1.17.0, have been addressed in 1.18.0. There are no workarounds or mitigations other than updating to the latest version. With vulnerabilities in Dell products (CVE-2021-21551 and CVE-2026-22769) having come under active exploitation in recent years, it’s essential to apply the necessary fixes for optimal protection.

    access Admin CSM Dell enable flaws Kubernetes nodes Root unauthenticated
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

    Crypto Scammers Hijack Microsoft’s Official X Account

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

    SWIFT Banking & Government Middleware Enables RCE

    In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 2, 2026

    Federal Judge Slams the Brakes on Big Bend Border Wall Construction

    October 2, 2026

    How Sea Cucumbers Drive Crime From China to Mexico

    October 2, 2026

    Flydubai pilot recounts cockpit stabbing in call with Indian PM Modi | Aviation News

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    IMF Praises El Salvador But Tries To Scale Back Bitcoin Use

    October 2, 2026

    Federal Judge Slams the Brakes on Big Bend Border Wall Construction

    October 2, 2026

    How Sea Cucumbers Drive Crime From China to Mexico

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.