Dell Fixes Storage Flaws That Could Expose Administrator Passwords

Dell has released version 1.18.0 of its Container Storage Modules software, closing two flaws the company rates at 10.0, the top of the CVSS scale vendors use to rank severity. Dell classifies both as missing authentication: the affected service accepted instructions from anyone who could reach it over the network, without first checking who was asking.
Container Storage Modules is the software that lets applications running in Kubernetes clusters request storage from Dell arrays. Dell says the first flaw, CVE-2026-63688, is in a part of the authorization module that handles storage credentials. An attacker who has not logged in but can reach it over the network could obtain the administrator credentials for every storage array a cluster has registered, across all five Dell storage product families the software supports. The second, CVE-2026-63692, could hand the same kind of attacker administrative control of the component that decides who may reach which array.
Dell's advisory, DSA-2026-448, published Oct. 1, 2026, lists six flaws in Dell's own code scored at 9.6 or above. They include one the company says could give a user with low privileges full control of every machine in a Kubernetes cluster, and two caused by credentials written into the software itself. The advisory also covers vulnerabilities in third-party Go libraries shipped with the product.
Versions before 1.17.0 are affected and 1.18.0 or later is the fix, Dell says, and it lists no workarounds or mitigations. One of the hard-coded credential flaws is in a component Dell has since archived; the company notes that the key in question appeared in that component's own public configuration documentation, which was later taken down, so anyone who set it up from that guide and never changed the key may still be exposed.
The severity scores are Dell's own assessment. The advisory makes no mention of any of these flaws having been exploited.
