Critical

Dell, CSM, Container Storage Modules, CVE-2026-63688, Kubernetes, privilege escalation, hard-coded credentials, root

Dell CSM CVE-2026-63688: Root on Kubernetes Nodes

Dell CSM CVE-2026-63688 leads six critical flaws (two CVSS 10.0) giving unauthenticated admin and root on Kubernetes nodes. Patch to CSM 1.18.0 now.

Dell CSM CVE-2026-63688 is one of six critical flaws in Dell Container Storage Modules, two of them rated CVSS 10.0, that together let an unauthenticated attacker gain administrative access and escalate to root on Kubernetes cluster nodes. The flaws span missing authentication, hard-coded credentials and keys, privilege escalation, and template injection, and some are being actively exploited, so upgrade CSM to version 1.18.0 now.

Container Storage Modules are Dell's storage-orchestration layer for Kubernetes, the component that connects clusters to Dell storage arrays. Because CSM runs with deep cluster privileges and brokers credentials for every registered array, a chain of flaws here is close to a worst case: it reaches both the storage backend and the nodes that run your workloads. According to The Hacker News and BleepingComputer, Dell is urging immediate patching, noting that its products have been targeted after past disclosures.

The six vulnerabilities combine into several complete attack paths. CVE-2026-63688 (CVSS 10.0) is an unauthenticated gRPC server that exposes storage-array administrator credentials for every registered array. CVE-2026-63692 (10.0) is an authorization bypass that grants administrative privileges. CVE-2026-67269 (9.9) escalates through a Custom Resource reconciler to root on cluster nodes. Two more, CVE-2026-54472 (9.8) and CVE-2026-61421 (9.8), are hard-coded credentials and a publicly known JWT signing secret that let an attacker forge administrative tokens, and CVE-2026-67273 (9.6) is a template injection that tampers with RBAC and reads Kubernetes Secrets cluster-wide. Each targets the trust that a cluster places in its storage layer.

What is CSM and why is this so severe?

Dell CSM is the bridge between Kubernetes and Dell storage, so it necessarily holds array credentials and runs privileged controllers inside the cluster. That position is the reason the severity is stacked: missing authentication on its gRPC server leaks backend admin credentials, forged tokens grant administrative control, and a privilege-escalation path reaches root on the nodes themselves. When one component can both read every Kubernetes Secret and gain root on nodes, compromising it is effectively compromising the cluster and the data behind it.

Which versions are affected and how do I fix it?

Detail

Value

Affected

All Dell Container Storage Modules before 1.17.0

Fixed

Version 1.18.0 (no workarounds)

Highest severity

CVE-2026-63688 and CVE-2026-63692 (CVSS 10.0)

Flaw classes

Missing authentication, hard-coded credentials and JWT key, privilege escalation to root, template injection

Exploitation

Active exploitation confirmed for some of the flaws

Upgrade CSM to 1.18.0, since there are no workarounds. Because hard-coded credentials and a known signing key are involved, assume any token or credential those components protected could be forged, and rotate storage-array and cluster credentials after patching. Treat clusters that exposed the CSM gRPC server as potentially compromised and hunt accordingly.

Our read

Hard-coded credentials, a published JWT secret, and a missing-authentication gRPC server are the kind of findings that make a "we use Kubernetes securely" statement hollow, because the exposure was shipped in a trusted component, not introduced by a misconfiguration you could spot in review. That is exactly the class of risk continuous verification exists to catch: a privileged storage controller that can reach root on nodes and read every Secret is a single point of total compromise, and the only honest way to know your exposure is to confirm which clusters run an affected CSM version and whether its endpoints are reachable. Privilege escalation to root on the nodes is the step that turns one weak component into control of everything, so rank this by what it grants, cluster-wide compromise, rather than by whether a scanner has caught up to CVEs the NVD has not yet scored.

Reporting by The Hacker News and BleepingComputer; CVSS ratings and flaw detail per Dell's security advisory. Sources linked above.

Frequently asked questions

What is CVE-2026-63688?
It is a CVSS 10.0 flaw in Dell Container Storage Modules: an unauthenticated gRPC server that exposes storage-array administrator credentials for every registered array, part of a set of six critical CSM vulnerabilities.

How do I fix the Dell CSM vulnerabilities?
Upgrade Dell Container Storage Modules to version 1.18.0. All versions before 1.17.0 are affected and there are no workarounds. After patching, rotate storage-array and cluster credentials, since hard-coded credentials and a known signing key are involved.

Are the Dell CSM flaws being exploited?
Dell reports active exploitation for some of the flaws and is urging immediate patching, citing past targeting of its products after disclosures.

What can an attacker do with these flaws?
Chain them to obtain storage-backend admin credentials, forge administrative tokens, escalate to root on Kubernetes nodes, and read Kubernetes Secrets cluster-wide, effectively a full cluster compromise.

Writing your own code with AI? The same bug classes surface there too. Scan your code free with Argus ›
Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.
AI CODE SECURITY
Catch the bug before it ships
Argus scans your repos for the vulnerability classes behind today's CVEs.
›Prioritized by real exploit data
›Connect a repo in minutes
Run a free scan
Live NVD · EPSS · CISA KEV