Sceawere
Vulnerability Detail
CVE-2026-63688UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell CSM Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 10h ago
- Vendor
- Dell
- Product
- Dell Container Storage Modules (CSM)
- Attack Type
- CWE-306: Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-06T15:17:18.890Z",
"pubdate": "2026-10-06T15:17:18.890Z",
"executiveSummary": "Dell Container Storage Modules (CSM) versions prior to v1.18.0 are susceptible to a critical Missing Authentication for Critical Function vulnerability within the csm-authorization-storage gRPC server.\nThis flaw allows an unauthenticated remote attacker to bypass security controls and gain unauthorized access to administrative credentials for integrated storage backends.\nThe vulnerability represents a severe risk to infrastructure integrity, as successful exploitation grants attackers full administrative control over all registered storage arrays.\nThe attack vector is network-based, requiring no authentication to interact with the vulnerable gRPC service, thereby posing a significant threat to internal storage management planes.\nOrganizations utilizing CSM should prioritize an immediate upgrade to version 1.18.0 or later to remediate the authentication oversight.",
"technicalDetails": "The vulnerability resides within the csm-authorization-storage gRPC service, which serves as a central component for managing authorization and access control for Dell storage backends.\nThe root cause is identified as a Missing Authentication for Critical Function vulnerability, where the gRPC server fails to validate the identity of incoming requests before processing them.\nIn a secure implementation, the gRPC service should enforce robust mTLS or token-based authentication for every request directed at sensitive administrative functions.\nDue to the absence of these mandatory checks, the service implicitly trusts requests arriving over the network, permitting unauthorized entities to invoke backend administrative commands.\nThe attack flow proceeds as follows: 1) An unauthenticated attacker probes the network to locate the csm-authorization-storage gRPC endpoint; 2) The attacker crafts a request using the gRPC protocol targeting the storage backend credential management functions; 3) Because the service lacks sufficient authorization logic, the request is executed with administrative privileges; 4) The attacker extracts the stored administrator credentials for all registered storage arrays.\nExploitation does not require prior knowledge of legitimate user accounts, as the service does not enforce authentication requirements before the logic branch responsible for credential handling is reached.\nThe impact of this vulnerability is total compromise of the storage layer. By retrieving administrator credentials, an attacker gains the ability to provision or delete volumes, modify storage configuration, or exfiltrate sensitive data stored across the array cluster.\nAffected versions include all CSM deployments prior to v1.18.0. The vulnerability is characterized as high-severity due to the lack of complexity required to bypass the authentication barrier and the catastrophic potential for post-exploitation data access and storage manipulation.\nPost-exploitation activities are limited only by the privileges associated with the compromised credentials, which, in the context of storage administrators, typically encompass full read/write/delete capabilities across all integrated storage fabric components."
}