ALEXKRI.NET
Resume Contact
← Back

Dell asks admins to patch max severity CSM flaws as soon as possible

The CSI driver is the layer nobody puts in the threat model, and it quietly holds credentials for every array behind it. Two max-severity flaws in Dell Container Storage Modules hand over storage backend admin credentials for all registered arrays (CVE-2026-63688) and full control of the authorization service (CVE-2026-63692). Four more criticals get root on cluster nodes and bypass Kubernetes controls to read secrets. Fix is CSM 1.18.0.

Read the source ↗