hacker-news · Crawled Oct 2, 2026

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Read original article ↗

AI Summary

Dell has disclosed multiple critical vulnerabilities in its Container Storage Modules (CSM) affecting versions prior to 1.17.0, which were patched in version 1.18.0. The most severe flaws include CVE-2026-63688 and CVE-2026-63692, both with a CVSS score of 10.0, enabling unauthenticated remote attackers to gain administrative access to storage infrastructure and Kubernetes clusters. Exploitation of these vulnerabilities could allow full control over storage systems, privilege escalation to root, and unauthorized manipulation of access policies across tenants.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.