PT-2026-104558 · Undefined · Undefined

CVE-2026-76105

·

Published

2026-10-03

·

Updated

2026-10-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
🚨 DELL CONTAINER STORAGE MODULES — UNAUTHENTICATED CVSS 10.00 (DSA-2026-448)
Dell Security Advisory DSA-2026-448, revision 1.0, dated 1 Oct 2026, covers multiple vulnerabilities in Dell Container Storage Modules. Article 000515771. Impact: Critical.
Unauthenticated missing authentication, CVSS 10.00: • CVE-2026-63688 — CSM Authorization 2.4.0. Missing authentication on the csm-authorization-storage gRPC server. An unauthenticated remote attacker could reach storage-backend administrator credentials for all registered storage arrays. • CVE-2026-63692 — CSM Authorization v2.4.0. Missing authentication in the authorization proxy and tenant service. An unauthenticated network attacker could bypass authentication and take administrative control of the authorization service across tenants.
Cluster-node root, CVSS 9.9: • CVE-2026-67269 — CSM Operator 1.12.0. Improper privilege management in the ContainerStorageModule custom-resource reconciler. A low-privileged remote attacker could gain root on cluster nodes.
Hard-coded JWT / credentials, CVSS 9.8: • CVE-2026-54472 — hard-coded credentials in CSM Authorization 2.4.0. A remote unauthenticated attacker could forge administrative tokens. Dell says upgrade and immediately rotate any JWT signing secrets. • CVE-2026-61421 — hard-coded cryptographic key in the JWT component of archived karavi-authorization. A remote unauthenticated attacker who knows the documented signing secret could forge tokens and gain administrative privileges.
Product table: • Affected: Container Storage Modules, versions prior to 1.17.0 • Remediated: version 1.18.0 or later • Workarounds and mitigations: None
⚠️ Analyst Note:
This is Dell's vendor advisory. The page does not claim active exploitation, and it does not place these CVEs in CISA KEV. Scores above are Dell's CVSS base scores (written 10.00, 9.9, and 9.8).
The remediation table lists 1.18.0 or later for versions prior to 1.17.0. The same advisory also lists CVE-2026-76105, CVSS 7.7, local, insufficiently random values, against version v1.18.0. JWT rotation is stated in the CVE-2026-54472 text, not as a workaround. The workaround section says None.
#DDW #DarkWeb #Dell #CVE #CVE202663688 #CyberSecurity #ThreatIntelligence
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-76105

Affected Products

Undefined