Dell published security advisory DSA-2026-448 on October 1 for its Container Storage Modules (CSM). The advisory lists six flaws scored between 9.6 and 10.0 and seven lower-scored ones. It lists versions before 1.17.0 as affected and 1.18.0 or later as the fixed version.

Two of the flaws score 10.0. CVE-2026-63688 is missing authentication in the csm-authorization-storage gRPC server, and Dell says it allows unauthorized access to storage backend administrator credentials. CVE-2026-63692 is missing authentication in the authorization proxy and tenant service, which Dell says lets an unauthenticated attacker gain complete administrative control. The other four are CVE-2026-67269 (9.9, improper privilege management that Dell says allows root-level access on cluster nodes), CVE-2026-54472 (9.8, hard-coded credentials that allow forged administrative tokens), CVE-2026-61421 (9.8, a hard-coded cryptographic key with a publicly documented signing secret in the archived karavi-authorization component) and CVE-2026-67273 (9.6, a template engine flaw that Dell says grants cluster-wide read access to Kubernetes Secrets).

Dell recommends upgrading at the earliest opportunity. For CVE-2026-54472 it also says to rotate any JWT signing secrets. The advisory documents no workarounds, and we found no mention of exploitation in it.

Our read: four of the six top flaws come down to authentication that is missing or built on a secret that was fixed in advance, which makes upgrading only half the job. Because one of the signing secrets is documented publicly, teams should rotate their JWT signing secrets after the upgrade and review authorization proxy logs for administrative activity they cannot explain. Storage credentials held in a cluster follow the same rules as any other privileged secret, as we noted in our report on Kubernetes operators with more access than they need and in the Artifactory admin access flaw CISA listed.

Source: Dell, DSA-2026-448: Security Update for Dell Container Storage Modules