№275|08:43 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Dell Patches Six Maximum-Severity Container Storage Flaws That Grant Admin Access

Dell has patched six critical-severity vulnerabilities in its Container Storage Modules, including two maximum-severity flaws that allow unauthenticated remote attackers to gain full administrative control over enterprise storage infrastructure connected to Kubernetes environments.

SM
Sara Montes de Oca
OCT 2, 2026 · 07:01 PM ET · 2 MIN READ
via Wikipedia (Dell Technologies)

Dell has released patches for six critical-severity vulnerabilities in its Container Storage Modules (CSM), including two flaws rated at maximum severity that allow unauthenticated remote attackers to seize full administrative control over enterprise storage infrastructure, the company said Thursday.

CSM is the software layer that connects Dell's enterprise storage arrays — including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT — to Kubernetes environments, extending the capabilities of standard Container Storage Interface drivers.

The two maximum-severity flaws, first reported by BleepingComputer, both reside in the Dell CSM Authorization security module and stem from what Dell describes as "missing authentication for critical functions" weaknesses.

The first, tracked as CVE-2026-63688, allows an unauthenticated remote attacker to access storage backend administrator credentials for all registered storage arrays and bypass authorization to gain full administrative control over the storage infrastructure.

The second, CVE-2026-63692, is present in the authorization proxy and tenant service. Dell warned in its security advisory that the flaw "enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants."

Alongside those two, Dell patched four additional critical-severity CSM vulnerabilities. CVE-2026-67269 allows remote attackers without privileges to gain root access on cluster nodes. CVE-2026-54472 enables unauthorized administrative access to the CSM Authorization proxy. CVE-2026-61421 permits attackers to forge authentication tokens and obtain administrative privileges. CVE-2026-67273 allows cluster-wide read access to Kubernetes Secrets by bypassing Kubernetes access controls.

All six flaws can be exploited remotely and without authentication, raising the potential exposure for enterprises running unpatched versions of the software.

Dell said it has not yet flagged any of the six vulnerabilities as actively exploited in the wild. The company is nonetheless urging customers to treat the update as urgent, advising organizations to upgrade their container storage modules to version 1.18.0 or later, which addresses all of the disclosed flaws. "Dell recommends customers to upgrade at the earliest opportunity," the company said in its advisory.

The disclosure comes amid a documented pattern of state-sponsored actors targeting Dell products. In a campaign revealed in February, Mandiant and Google's Threat Intelligence Group identified a suspected Chinese state-backed group, designated UNC6201, that had been exploiting a separate maximum-severity hardcoded-credential vulnerability — CVE-2026-22769 — in Dell RecoverPoint for Virtual Machines since at least mid-2024. Researchers found overlaps between UNC6201 and Silk Typhoon, a Chinese cyberespionage group known for targeting government agencies using custom malware in Ivanti zero-day attacks. Days after that disclosure, the U.S. Cybersecurity and Infrastructure Security Agency ordered federal agencies to patch affected Dell systems within three days.

North Korea's Lazarus Group has also previously exploited Dell hardware, deploying a Windows rootkit by abusing an access control vulnerability tracked as CVE-2021-21551 in the Dell dbutil driver.

With critical Kubernetes storage infrastructure now in the crosshairs, the speed at which enterprise administrators apply version 1.18.0 will determine whether Thursday's advisory becomes a footnote or the starting point of a broader incident investigation.

SM
━ ABOUT THE REPORTER
Sara Montes de Oca

Sara Montes de Oca is the Editor in Chief of TechEchelon. Previously a correspondent and producer in Washington, D.C., covering business, finance, and politics.

More from Sara →
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime