PT-2026-104558 · Undefined · Undefined
CVE-2026-76105
·
Publicado
2026-10-03
·
Atualizado
2026-10-03
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
🚨 DELL CONTAINER STORAGE MODULES — UNAUTHENTICATED CVSS 10.00 (DSA-2026-448)
Dell Security Advisory DSA-2026-448, revision 1.0, dated 1 Oct 2026, covers multiple vulnerabilities in Dell Container Storage Modules. Article 000515771. Impact: Critical.
Unauthenticated missing authentication, CVSS 10.00:
• CVE-2026-63688 — CSM Authorization 2.4.0. Missing authentication on the csm-authorization-storage gRPC server. An unauthenticated remote attacker could reach storage-backend administrator credentials for all registered storage arrays.
• CVE-2026-63692 — CSM Authorization v2.4.0. Missing authentication in the authorization proxy and tenant service. An unauthenticated network attacker could bypass authentication and take administrative control of the authorization service across tenants.
Cluster-node root, CVSS 9.9:
• CVE-2026-67269 — CSM Operator 1.12.0. Improper privilege management in the ContainerStorageModule custom-resource reconciler. A low-privileged remote attacker could gain root on cluster nodes.
Hard-coded JWT / credentials, CVSS 9.8:
• CVE-2026-54472 — hard-coded credentials in CSM Authorization 2.4.0. A remote unauthenticated attacker could forge administrative tokens. Dell says upgrade and immediately rotate any JWT signing secrets.
• CVE-2026-61421 — hard-coded cryptographic key in the JWT component of archived karavi-authorization. A remote unauthenticated attacker who knows the documented signing secret could forge tokens and gain administrative privileges.
Product table:
• Affected: Container Storage Modules, versions prior to 1.17.0
• Remediated: version 1.18.0 or later
• Workarounds and mitigations: None
⚠️ Analyst Note:
This is Dell's vendor advisory. The page does not claim active exploitation, and it does not place these CVEs in CISA KEV. Scores above are Dell's CVSS base scores (written 10.00, 9.9, and 9.8).
The remediation table lists 1.18.0 or later for versions prior to 1.17.0. The same advisory also lists CVE-2026-76105, CVSS 7.7, local, insufficiently random values, against version v1.18.0. JWT rotation is stated in the CVE-2026-54472 text, not as a workaround. The workaround section says None.
Primary:
https://t.co/FLNCVgg5wj
#DDW #DarkWeb #Dell #CVE #CVE202663688 #CyberSecurity #ThreatIntelligence
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined