PT-2026-104557 · Undefined · Undefined
CVE-2026-67269
·
Publicado
2026-10-03
·
Atualizado
2026-10-03
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Dell's CSM advisory has two 10.0 flaws among 13. The "root on nodes" one is a 9.9 needing low privileges
2 of 13. Dell advisory DSA-2026-448 lists 37 CVEs: 13 in Dell's own code, two scored 10.0 and six scored 9.6 or more. Workarounds: "None". Fix: version 1.18.0 or later. The headline pairing, unauthenticated admin plus root on nodes, merges two different flaws. The two 10.0s are in CSM Authorization, need no login, and sit in the proxy that holds the administrator credentials for every registered array. Root on nodes is CVE-2026-67269 in the CSM Operator, scored 9.9, and Dell calls the attacker low privileged.
🧮 We recomputed all 13 scores from their vectors and every one matches. Four are scored Network with no privileges: the two 10.0 rows and two 9.8 rows (hard-coded credentials, and a signing secret Dell says its documentation published).
🔍 The affected range is "versions prior to 1.17.0", yet two rows name operator 1.12.0, which Dell's own repository labels as the 1.17 line. So 1.17.x sits in neither column. One row names the fixed version, 1.18.0, as affected, and four rows still read "[Versions]".
⚖️ At 11:15 BST on 3 October, no CVE record or NVD entry existed for any of the 13, so every score is Dell's alone. None is in CISA KEV. The advisory says nothing on exploitation and names no finder. "Network" is a ceiling, not a position; Dell's documentation says the proxy is exposed through an Ingress, so who can reach it is a fact about your network.
🔑 For the service that exists to keep array passwords away from Kubernetes administrators, who has written down which networks can reach it?
Full briefing: https://t.co/Tv3txwaws8
#Dell #DellCSM #Kubernetes #CVE #CVSS #StorageSecurity #VulnerabilityManagement #KEV #CloudNative #InfoSec #CyberSecurity #CISO #SecOps #UKTech
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined