Sceawere
Vulnerability Detail
CVE-2026-70411UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Dell CSM Tenant Authentication Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 9h ago
- Vendor
- Dell
- Product
- Container Storage Modules (CSM)
- Attack Type
- CWE-306: Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-06T16:17:09.877Z",
"pubdate": "2026-10-06T16:17:09.877Z",
"executiveSummary": "Dell Container Storage Modules (CSM) versions prior to 1.18.0 are susceptible to a Missing Authentication for Critical Function vulnerability within the csm-authorization-tenant gRPC service.\nThe vulnerability allows an unauthenticated attacker located on an adjacent network to interact directly with the TenantService, bypassing existing security controls.\nSuccessful exploitation enables unauthorized administrative actions, including the creation of rogue tenant entities, the injection of malicious cross-tenant roles, and the arbitrary modification of storage access control flags.\nThis flaw represents a significant security risk, as it permits unauthorized manipulation of storage infrastructure and multi-tenant isolation boundaries.\nThe lack of enforced authentication in the gRPC service enables attackers to influence system state without valid credentials, potentially leading to unauthorized data access, storage resource exhaustion, or administrative privilege escalation.\nOrganizations are advised to upgrade to the remediated version to restore critical access controls and protect the integrity of the storage environment.",
"technicalDetails": "The vulnerability originates from a Missing Authentication for Critical Function flaw located within the csm-authorization-tenant gRPC service. Specifically, the TenantService interface fails to validate the identity or authorization context of requests before processing sensitive operations.\nThe root cause is the absence of an authentication middleware or interceptor within the gRPC service stack that should enforce verification of caller credentials before allowing method execution. Because the service does not perform these checks, it treats incoming network requests as trusted, even when originating from unauthenticated, remote, or adjacent network sources.\nThe attack flow proceeds as follows: 1) The attacker identifies the exposed csm-authorization-tenant gRPC service, typically listening on an internal network port. 2) The attacker crafts a malicious gRPC message targeting the TenantService methods. 3) Because the service lacks authentication headers or cryptographic token validation, the service accepts and executes the request. 4) The attacker invokes methods designed for tenant management, such as those responsible for creating, deleting, or updating entity metadata.\nExploitation allows the attacker to perform several critical operations. First, an attacker can create new tenant entities, effectively bypassing isolation policies. Second, they can perform cross-tenant role injection, which allows the unauthorized assignment of permissions that should be confined to a specific administrative scope. Third, the attacker can modify storage access control flags; this is particularly severe as it can grant unauthorized entities read/write access to storage volumes or override security policies configured for legitimate tenants.\nThe attack vector requires network proximity to the affected CSM instance, typically within an adjacent network segment. No specific user interaction is required, and no elevated privileges are initially necessary for the attacker to begin issuing commands to the service. The impact is significant, as it fundamentally breaks the multi-tenancy model of the storage module, potentially leading to full administrative compromise of the managed storage resources and the ability to pivot into cross-tenant environments, thereby violating data isolation and confidentiality requirements."
}