Skip to content
See the World Through ScienceA project of ALLATRA

Dell Fixes Storage Flaws That Could Expose Administrator Passwords

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Close-up of a rack mounted server above rows of hot swap drive carriers with green status lights.
Hot-swap drive carriers in a rack enclosure. Storage hardware like this is reached over a network by software that is supposed to check who is asking first (illustrative)."HP Server & Disk Array" by Bob Mical, via flickr, BY-NC · CC-BY-NC-2.0

Dell has released version 1.18.0 of its Container Storage Modules software, closing two flaws the company rates at 10.0, the top of the CVSS scale vendors use to rank severity. Dell classifies both as missing authentication: the affected service accepted instructions from anyone who could reach it over the network, without first checking who was asking.

Container Storage Modules is the software that lets applications running in Kubernetes clusters request storage from Dell arrays. Dell says the first flaw, CVE-2026-63688, is in a part of the authorization module that handles storage credentials. An attacker who has not logged in but can reach it over the network could obtain the administrator credentials for every storage array a cluster has registered, across all five Dell storage product families the software supports. The second, CVE-2026-63692, could hand the same kind of attacker administrative control of the component that decides who may reach which array.

Dell's advisory, DSA-2026-448, published Oct. 1, 2026, lists six flaws in Dell's own code scored at 9.6 or above. They include one the company says could give a user with low privileges full control of every machine in a Kubernetes cluster, and two caused by credentials written into the software itself. The advisory also covers vulnerabilities in third-party Go libraries shipped with the product.

Versions before 1.17.0 are affected and 1.18.0 or later is the fix, Dell says, and it lists no workarounds or mitigations. One of the hard-coded credential flaws is in a component Dell has since archived; the company notes that the key in question appeared in that component's own public configuration documentation, which was later taken down, so anyone who set it up from that guide and never changed the key may still be exposed.

The severity scores are Dell's own assessment. The advisory makes no mention of any of these flaws having been exploited.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Dell Fixes Storage Flaws That Could Expose Administrator Passwords

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.