- Dell said CVE-2026-67269 could let an attacker compromise every node in a Kubernetes cluster through one custom resource submission.
- The Hacker News said CSM versions before 1.17.0 are affected, while version 1.18.0 addresses the flaws.
- Dell recommends upgrading at the earliest opportunity and rotating JWT signing secrets for the hard-coded-credentials vulnerability.
Dell published a security update on Oct 1, 2026, for multiple critical vulnerabilities in its Container Storage Modules. The Hacker News reported that the flaws could let attackers take over susceptible systems.
The risk reaches Kubernetes environments using CSM. Dell said an attacker could exploit one of the vulnerabilities, CVE-2026-67269, to compromise every node in a Kubernetes cluster through a single custom resource submission.
BleepingComputer said CSM connects Dell enterprise storage arrays to Kubernetes environments. Dell also said its karavi-authorization component is archived and no longer actively maintained.
On this page
The six CVEs include two missing-authentication flaws
The Hacker News said CVE-2026-63688 and CVE-2026-63692 each have a CVSS score of 10.0 and involve missing authentication for a critical function.
It said CVE-2026-67269 has a CVSS score of 9.9 and involves improper privilege management. CVE-2026-54472 and CVE-2026-61421 each have a CVSS score of 9.8 and involve hard-coded credentials and a hard-coded cryptographic key, respectively.
CVE-2026-67273 has a CVSS score of 9.6 and involves improper neutralization of special elements used in a template engine, The Hacker News said.
Dell archived the affected authorization component
Dell said karavi-authorization contained the hard-coded cryptographic key vulnerability. The company described the component as archived and no longer actively maintained.
Dell’s advisory was initially released on Oct 1, 2026. The Hacker News said the flaws affect all CSM versions before 1.17.0 and are addressed in 1.18.0.
Dell said there are no workarounds or mitigations other than updating to the latest version. It recommends upgrading at the earliest opportunity and rotating JWT signing secrets for the hard-coded-credentials vulnerability.
What to do now
- Upgrade at the earliest opportunity and immediately rotate any JWT signing secrets.
FAQ
What happened in Dell Container Storage Modules?
The Hacker News said Dell released security updates for multiple critical vulnerabilities in CSM that could be exploited to take over susceptible systems.
Which Dell CSM versions are affected?
The Hacker News said all CSM versions before 1.17.0 are affected, and version 1.18.0 addresses the flaws.
Can one CSM flaw compromise a Kubernetes cluster?
Dell said an attacker could exploit CVE-2026-67269 to compromise every node in a Kubernetes cluster through a single custom resource submission.
What are the CVSS scores for the Dell CSM vulnerabilities?
The Hacker News said the scores are 10.0 for CVE-2026-63688 and CVE-2026-63692, 9.9 for CVE-2026-67269, 9.8 for CVE-2026-54472 and CVE-2026-61421, and 9.6 for CVE-2026-67273.
How do you fix the Dell CSM vulnerabilities?
Dell said there are no workarounds or mitigations other than updating to the latest version. It recommends upgrading at the earliest opportunity and rotating JWT signing secrets for the hard-coded-credentials vulnerability.
Sources
- DSA-2026-448: Security Update for Dell Container Storage Modules Multiple Vulnerabilities | Dell US, DellPrimary
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes, The Hacker News
- Dell asks admins to patch max severity CSM flaws as soon as possible, BleepingComputer
- Dell, Wikipedia
How we checked this story
| Claim | Source | Status |
|---|---|---|
| The Hacker News said dell released security updates for multiple critical vulnerabilities in Container Storage Modules that bad actors could exploit to take over susceptible systems. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-63688 has a CVSS score of 10.0. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-63692 has a CVSS score of 10.0. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-67269 has a CVSS score of 9.9. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-54472 has a CVSS score of 9.8. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-61421 has a CVSS score of 9.8. | The Hacker News | Attributed |
| The Hacker News said cVE-2026-67273 has a CVSS score of 9.6. | The Hacker News | Attributed |
| The Hacker News said dell Container Storage Modules versions before 1.17.0 are affected, and version 1.18.0 addresses the flaws. | The Hacker News | Attributed |
| Dell says karavi-authorization is archived and no longer actively maintained. | Dell | Confirmed |
| BleepingComputer reported that Dell patched two maximum-severity vulnerabilities connecting enterprise storage arrays to Kubernetes environments. | BleepingComputer | Attributed |
| Dell develops, sells, repairs, and supports personal computers, servers, storage devices, network switches, software, and peripherals. | Wikipedia | Confirmed |
| dell.com published its report on Oct 1, 2026. | dell.com | Confirmed |
Could not verify
- Whether any of the vulnerabilities were exploited in the wild is not established
- How many Dell customers or systems are affected is not established
- Whether CVE-2026-63688 and CVE-2026-63692 were the two vulnerabilities referenced by BleepingComputer is not established
- Whether all affected versions are covered by the listed remediation is not established



