TL;DR
Dell fixed two CVSS 10 flaws in its Container Storage Modules (CSM). These Dell Container Storage Modules vulnerabilities let unauthenticated attackers take full admin control of the storage layer. Upgrade to version 1.18.0 or later now.
- Total: 24 CVEs
- Severity: 9 Critical · 9 High · 5 Medium · 1 Low
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-46595
- Action: Apply the latest security updates now
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-46595 | 10 | CWE-863 | 0.52.0 | Not exploited |
| CVE-2026-39821 | 9.6 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | 1.25.13, 1.26.6, 1.27.0-rc.3 (+1) | Not exploited |
| CVE-2024-45337 | 9.1 | Misuse of connection.serverAuthenticate may cause authorization bypass in | 0.31.0 | Not exploited |
| CVE-2026-39830 | 9.1 | Invoking client can cause server deadlock on unexpected responses in | 0.52.0 | Not exploited |
| CVE-2026-39831 | 9.1 | CWE-862 | 0.52.0 | Not exploited |
| CVE-2026-39832 | 9.1 | CWE-502 | 0.52.0 | Not exploited |
| CVE-2026-39833 | 9.1 | CWE-862 | 0.52.0 | Not exploited |
| CVE-2026-39834 | 9.1 | CWE-190 | 0.52.0 | Not exploited |
Why It Matters
CSM connects Kubernetes clusters to Dell storage arrays such as PowerMax, PowerFlex, and PowerStore. As a result, a flaw here reaches past the cluster into the arrays themselves.
Many teams run CSM to give containers persistent storage in production. That means the authorization service often holds admin keys for every connected array. One stolen credential can therefore expose data far beyond a single app or namespace.
The advisory, DSA-2026-448, lists 13 Dell-specific CVEs and 24 more in third-party Go libraries. Dell rates the overall impact as Critical. So far, Dell has not reported any exploitation in the wild, and no public proof-of-concept has surfaced.
How the Attacks Work
Two Perfect-10 Authentication Gaps
CVE-2026-63688 sits in the csm-authorization-storage gRPC server. Dell says a remote attacker could gain “unauthorized access to storage backend administrator credentials for all registered storage arrays.” Moreover, Dell warns it gives “full administrative control over the storage infrastructure spanning all five supported Dell storage product families.”
CVE-2026-63692 hits the authorization proxy and tenant service. It allows a complete bypass of login checks. In turn, attackers could reach and change “storage resources across all tenants.”
Cluster Takeover Through the Operator
CVE-2026-67269 scores 9.9. It affects the CSM Operator’s custom resource reconciler. A low-privileged user could gain root on cluster nodes. According to Dell, an attacker could “completely compromise all nodes in the Kubernetes cluster through a single custom resource submission.”
Similarly, CVE-2026-67273 (9.6) abuses a template engine flaw. It grants cluster-wide read access to Kubernetes Secrets.
Hard-Coded Secrets
Two more bugs score 9.8. CVE-2026-54472 involves hard-coded credentials that let attackers forge valid admin tokens. Meanwhile, CVE-2026-61421 affects the archived karavi-authorization project. Its old setup guide showed a sample JWT signing secret. Any team that copied it and never rotated the key may still be exposed.
Lower-Severity Issues
The rest include log files that leak sensitive data, weak certificate checks, and missing authorization in CSI drivers. Third-party fixes cover golang.org/x/crypto, golang.org/x/net, golang-jwt, and protobuf.
Affected Versions
Dell lists Container Storage Modules versions prior to 1.17.0 as affected. However, several CVE entries name CSM Authorization 2.4.0, CSM Operator 1.12.0, and even version 1.18.0. Dell notes the table “may not be a comprehensive list of all affected supported versions.”
Patch and Mitigation Steps
Upgrade
Dell offers no workarounds. Teams should move to version 1.18.0 or later, per the Dell DSA-2026-448 security advisory.
Rotate Secrets
- Rotate every JWT signing secret, as Dell advises for CVE-2026-54472.
- Replace storage backend admin passwords that CSM stores.
- Retire any karavi-authorization deployment, since the project is no longer maintained.
Limit Access
Restrict network access to CSM authorization services. Finally, review RBAC roles for unexpected changes. These Dell Container Storage Modules vulnerabilities touch the keys to your storage, so act quickly.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!