Nube e infraestructura

Dell patches critical CSM flaws allowing unauthenticated Kubernetes root access

Dell released updates for Container Storage Modules to fix six critical vulnerabilities, including two with perfect CVSS scores, that allow unauthenticated remote attackers to gain admin or root acces

Este artículo está disponible solo en inglés.

Dell has issued emergency security patches for its Container Storage Modules (CSM) after researchers identified six critical vulnerabilities that could allow attackers to seize full control of Kubernetes clusters and storage infrastructure. The flaws, which affect all versions prior to 1.17.0, include two with perfect CVSS scores of 10.0 and were addressed in version 1.18.0 released on October 2, 2026.

What happened

The vulnerabilities span multiple components of the Dell CSM architecture, including the authorization proxy, tenant service, gRPC server, and JWT authentication modules. Two specific issues, CVE-2026-63688 and CVE-2026-63692, received the maximum severity rating of 10.0 because they involve missing authentication checks for critical functions. These gaps allow unauthenticated remote attackers to bypass security controls entirely. CVE-2026-63688 targets the csm-authorization-storage gRPC server, enabling attackers to retrieve storage backend administrator credentials for all registered arrays. Similarly, CVE-2026-63692 affects the authorization proxy and tenant service, granting administrative privileges without any valid login.

Other high-severity flaws include CVE-2026-67269, which carries a 9.9 CVSS score. This vulnerability stems from improper privilege management in the ContainerStorageModule Custom Resource reconciler. It allows a low-privilege remote attacker to escalate rights and obtain root-level access on cluster nodes by submitting a single custom resource. Additionally, CVE-2026-54472 and CVE-2026-61421, both scored 9.8, involve the use of hard-coded credentials and cryptographic keys. Attackers can exploit these to forge valid administrative tokens and bypass authentication for the CSM Authorization proxy. The final issue, CVE-2026-67273, is a template injection flaw with a 9.6 score that permits unauthorized RBAC tampering and access to sensitive Kubernetes Secrets.

How it works

These vulnerabilities exploit fundamental breakdowns in authentication and privilege enforcement within the CSM stack. In the case of the hard-coded credential flaws, the software contained static secrets or signing keys that were publicly known or easily derivable. An attacker does not need to brute-force a password; they simply use the known key to sign a JSON Web Token (JWT). The system accepts this forged token as legitimate because it was signed with the expected secret, granting the attacker administrative status instantly.

The missing authentication vulnerabilities operate by exposing internal gRPC endpoints and proxy services to the network without requiring any initial identity verification. Once connected, an attacker can send direct commands to the storage backend or tenant services. Because there is no gatekeeping mechanism at the entry point, the system processes these requests as if they came from a trusted administrator. The privilege escalation flaw leverages the Kubernetes reconciliation loop, where the system automatically adjusts state to match desired configurations. By injecting a malicious custom resource, the attacker tricks the reconciler into executing code with higher privileges than intended, effectively breaking out of the container sandbox to the host node.

Key details

  • CVE-2026-63688 (CVSS 10.0): Missing authentication in the gRPC server allows retrieval of storage admin credentials.
  • CVE-2026-63692 (CVSS 10.0): Missing authentication in the authorization proxy enables full administrative bypass.
  • CVE-2026-67269 (CVSS 9.9): Improper privilege management allows root access on nodes via custom resource submission.
  • CVE-2026-54472 (CVSS 9.8): Hard-coded credentials allow forging of administrative tokens for the authorization proxy.
  • CVE-2026-61421 (CVSS 9.8): Hard-coded JWT signing keys enable token forgery in the karavi-authorization component.
  • CVE-2026-67273 (CVSS 9.6): Template injection allows RBAC tampering and reading of Kubernetes Secrets.

Why it matters

For platform engineers and DevOps teams, these flaws represent a catastrophic failure of the supply chain security model. Dell CSM is widely used to manage persistent storage for stateful applications in Kubernetes. If an attacker exploits these vulnerabilities, they do not just compromise a single pod; they gain control over the underlying storage arrays and the cluster nodes themselves. This level of access allows for data exfiltration, ransomware deployment, or complete destruction of the infrastructure. The fact that two vulnerabilities have a perfect 10.0 score indicates that exploitation requires no user interaction and can be performed remotely by anyone with network access to the service endpoints.

The absence of workarounds makes immediate patching mandatory. Dell explicitly stated that there are no configuration changes or mitigations that can block these attacks other than upgrading to version 1.18.0. This places significant pressure on operations teams to schedule urgent maintenance windows. Furthermore, the recommendation to rotate JWT signing secrets implies that even after patching, organizations must assume that previous keys may have been compromised. Failure to rotate these secrets leaves the door open for attackers who may have already harvested the hard-coded values.

What you can do

  • Upgrade all Dell Container Storage Modules to version 1.18.0 or later immediately.
  • Rotate all JWT signing secrets used by the CSM Authorization module post-update.
  • Audit your Kubernetes clusters for any unknown Custom Resources submitted recently.
  • Review RBAC policies to ensure least-privilege access is enforced for service accounts.
  • Monitor network traffic for unusual connections to the csm-authorization-storage gRPC server.
  • Verify that storage backend administrator credentials have not been exposed or changed.

Herramientas de la Tienda de Bytechap

Seguir leyendo

Todos los artículos