Dell patches six critical flaws in Container Storage Modules for Kubernetes
Dell released fixes for six critical-severity vulnerabilities affecting its Container Storage Modules (CSM), which link enterprise storage arrays like PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT to Kubernetes clusters. Two of the flaws, found in the CSM Authorization module, let unauthenticated attackers obtain admin credentials and full control over storage infrastructure; the other four allow root access on cluster nodes, token forgery, proxy takeover, and unauthorized access to Kubernetes Secrets. Dell is urging customers to upgrade to CSM version 1.18.0 or later as soon as possible.
GoKawiil's interpretation of the reporting above, not reported fact.
Because the flaws require no authentication, any exposed CSM deployment could let an attacker seize administrative control over storage shared by multiple tenants, which is especially dangerous in multi-tenant cloud or enterprise Kubernetes environments. The breadth of affected Dell storage platforms suggests the risk extends across a large base of enterprise customers who rely on Dell for critical storage infrastructure. Dell's urgent patching guidance implies the company views exploitation as both plausible and highly damaging if left unaddressed.
- Dell fixed six critical vulnerabilities in its Container Storage Modules used to connect storage arrays to Kubernetes.
- Two flaws in the CSM Authorization module let unauthenticated attackers gain full admin control over storage infrastructure.
- Dell urges immediate upgrade to CSM version 1.18.0 or later to close the security gaps.
Source: bleepingcomputer.com, 2026-10-02
Published there as: “Dell asks admins to patch max severity CSM flaws as soon as possible”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.