PT-2026-104557 · Undefined · Undefined

CVE-2026-67269

·

Published

2026-10-03

·

Updated

2026-10-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Dell's CSM advisory has two 10.0 flaws among 13. The "root on nodes" one is a 9.9 needing low privileges
2 of 13. Dell advisory DSA-2026-448 lists 37 CVEs: 13 in Dell's own code, two scored 10.0 and six scored 9.6 or more. Workarounds: "None". Fix: version 1.18.0 or later. The headline pairing, unauthenticated admin plus root on nodes, merges two different flaws. The two 10.0s are in CSM Authorization, need no login, and sit in the proxy that holds the administrator credentials for every registered array. Root on nodes is CVE-2026-67269 in the CSM Operator, scored 9.9, and Dell calls the attacker low privileged.
🧮 We recomputed all 13 scores from their vectors and every one matches. Four are scored Network with no privileges: the two 10.0 rows and two 9.8 rows (hard-coded credentials, and a signing secret Dell says its documentation published).
🔍 The affected range is "versions prior to 1.17.0", yet two rows name operator 1.12.0, which Dell's own repository labels as the 1.17 line. So 1.17.x sits in neither column. One row names the fixed version, 1.18.0, as affected, and four rows still read "[Versions]".
⚖️ At 11:15 BST on 3 October, no CVE record or NVD entry existed for any of the 13, so every score is Dell's alone. None is in CISA KEV. The advisory says nothing on exploitation and names no finder. "Network" is a ceiling, not a position; Dell's documentation says the proxy is exposed through an Ingress, so who can reach it is a fact about your network.
🔑 For the service that exists to keep array passwords away from Kubernetes administrators, who has written down which networks can reach it?
#Dell #DellCSM #Kubernetes #CVE #CVSS #StorageSecurity #VulnerabilityManagement #KEV #CloudNative #InfoSec #CyberSecurity #CISO #SecOps #UKTech
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-67269

Affected Products

Undefined