PT-2026-104448 · Undefined · Undefined

CVE-2026-63689

·

Published

2026-10-02

·

Updated

2026-10-02

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Two critical vulnerabilities in Dell Container Storage Modules (CSM) allow unauthenticated attackers to gain admin access and compromise Kubernetes worker nodes. Patches are available now.
Technical Breakdown - CVE-2026-63688 (CVSS 10.0): Missing authentication in the csm-authorization-storage gRPC server. An unauthenticated attacker can call privileged functions, granting full admin control over the storage authorization system. - CVE-2026-63689 (CVSS 9.6): Path traversal in the CSM operator. Allows an attacker with network access to write arbitrary files to the host filesystem of a Kubernetes worker node, leading to remote code execution (RCE) and node compromise. - Affected: Dell Container Storage Modules (CSM) versions prior to the latest security release. - Impact: Full cluster compromise, data exfiltration, and lateral movement within the Kubernetes environment.
Defense Immediately update to the latest patched version of Dell CSM. If immediate patching is not possible, restrict network access to the gRPC endpoint (port 8082 by default) and the CSM operator service to trusted management networks only. Monitor for unusual API calls to the authorization service.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63689

Affected Products

Undefined