Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released updates for multiple critical flaws in Dell Container Storage Modules (CSM) that could let attackers bypass authentication, steal credentials, and gain administrative or root access across storage infrastructure and Kubernetes clusters. The issues affect CSM versions prior to 1.17.0 and are fixed in 1.18.0, with Dell urging customers to update immediately and rotate JWT signing secrets. #Dell #DellCSM #CVE-2026-63688 #CVE-2026-63692 #CVE-2026-67269 #CVE-2026-54472 #CVE-2026-61421 #CVE-2026-67273

Keypoints

  • Dell patched multiple critical flaws in Dell Container Storage Modules.
  • Several bugs could let unauthenticated attackers gain administrative control.
  • One vulnerability can expose storage backend administrator credentials.
  • A privilege escalation flaw could give root access on Kubernetes cluster nodes.
  • All CSM versions before 1.17.0 are affected, and 1.18.0 contains the fixes.

Read More: https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html