BlackTree Security · Infrastructure · Automation · AI

Dell CSM critical flaws meet conflicting patch guidance

Dell rates six Container Storage Modules flaws critical. CVE-2026-63688 and CVE-2026-63692 in CSM Authorization 2.4.0 threaten storage administrator credentials or cross-tenant control. CVE-2026-67269 risks node root; CVE-2026-67273, Secrets and RBAC; CVE-2026-54472 and CVE-2026-61421, forged admin tokens.

Version conflict

Dell’s table marks pre-1.17.0 affected and 1.18.0 onward remediated; 1.17.0 is unclear. Its CVE-2026-76105 description calls 1.18.0 affected. A universally safe version is unproven.

Signing-secret warnings

Dell recommends immediate JWT signing-secret rotation for CVE-2026-54472. Its separate CVE-2026-61421 warning concerns the archived karavi-authorization project and deployments following its removed guide, which showed a signing secret and live token output.

Operator response

Inventory components and versions. Ask Dell to resolve the conflict before closing remediation. Dell does not confirm exploitation.

Source: Dell DSA-2026-448, revision 1.0, 1 October 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *