Interestana
Home/News/Dell CSM Flaws Grant Unauthenticated Admin Access on Kubernetes
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Dell CSM Flaws Grant Unauthenticated Admin Access on Kubernetes

Dell CSM Flaws Grant Unauthenticated Admin Access on Kubernetes

Dell has issued security advisories and released updates to mitigate several critical vulnerabilities discovered within its Container Storage Modules (CSM). These flaws, if exploited, could allow unauthorized actors to gain administrative control over affected systems and achieve root-level privileges on Kubernetes nodes. The vulnerabilities span multiple components of the CSM software suite, highlighting a broad security concern for users deploying Dell's storage solutions in containerized environments.

One of the most severe vulnerabilities, identified as CVE-2026-63688, carries a perfect CVSS score of 10.0. This critical flaw resides in the csm-authorization-storage gRPC server and is characterized as a missing authentication for critical functions. This means an attacker could bypass authentication mechanisms entirely, directly accessing and potentially manipulating sensitive authorization functions within the storage module. Such a bypass could lead to complete system compromise without the need for any legitimate credentials.

Another significant vulnerability, CVE-2026-63689, also rated with a CVSS score of 10.0, affects the csm-provisioner component. This flaw is described as an improper access control vulnerability. Improper access control issues typically arise when a system fails to adequately restrict what authenticated users can do, or in this case, it might allow unauthenticated users to perform actions they should not be able to. The consequence is the potential for unauthorized operations that could lead to data manipulation or system takeover.

Further compounding the security risks, CVE-2026-63690, with a CVSS score of 9.8, is an improper access control vulnerability within the csm-snapshot-controller. This vulnerability could allow attackers to perform unauthorized snapshot operations, potentially leading to data loss, unauthorized data access, or disruption of backup and recovery processes. The high CVSS score indicates a severe impact on confidentiality, integrity, and availability.

Additionally, CVE-2026-63691, rated at CVSS 9.8, is an improper access control vulnerability in the csm-resizer component. This flaw could enable attackers to manipulate storage volume resizing operations, potentially leading to denial-of-service conditions or unauthorized modifications to storage configurations. The cumulative effect of these vulnerabilities presents a substantial risk to organizations relying on Dell CSM for their Kubernetes storage infrastructure. Dell has provided updated versions of the affected CSM components to address these security weaknesses, urging customers to apply the patches promptly to protect their environments from potential exploitation.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next