ZERO
Back
vulnerabilityCVE-2026-63688

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

A missing authentication for a critical function in the csm-authorization-storage gRPC server could allow an unauthenticated remote attacker to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays.

Severity
10.0Critical
Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action