3 OCT 2026 — Companies that run Kubernetes on Dell storage arrays often use Container Storage Modules, an open-source suite from Dell, to connect the two and control who can use which storage. On 1 October Dell published fixes for 13 flaws in that suite. Six are rated critical and two score the maximum 10. One stems from Dell's own documentation, which once showed administrators a signing secret that was simply "supersecret".
Dell says it is not aware of any exploitation. It tells customers to update to version 1.18.0 or later.
The worst of the flaws
The top-rated flaw, CVE-2026-63688 at 10.0, sits in the authorization module's storage service. Dell's advisory says an unauthenticated attacker over the network could obtain the administrator credentials for every storage array registered with it, a complete bypass of the module's security. A second 10.0, CVE-2026-63692, in the authorization proxy and tenant service, lets an unauthenticated attacker skip authentication and take administrative control.
Another, CVE-2026-67269 at 9.9, lets a low-privileged attacker gain root on cluster nodes. Dell says that could compromise every node in the Kubernetes cluster. A third, CVE-2026-54472 at 9.8, comes from hard-coded credentials that let an unauthenticated attacker forge valid administrator tokens.
The documented secret
The most unusual entry, CVE-2026-61421 at 9.8, sits in karavi-authorization, an older component now archived and no longer maintained. Dell's advisory says the official configuration documentation "demonstrated supersecret as the JWT signing secret alongside real token output," and that the page "was subsequently removed without a security advisory."
Any organisation that set up karavi-authorization from that guide and never changed the secret "may remain vulnerable," Dell says. The secret was public, so an attacker could forge login tokens and gain administrative rights without credentials. Updating the software does not fix this one by itself. The secret has to be changed.
A familiar kind of flaw
Hard-coded and default credentials are a familiar problem in serious appliance flaws. This year, attackers went on to exploit a hard-coded password in Cisco's firewall manager.
The rest of the list
The sixth critical flaw, CVE-2026-67273 at 9.6, lets a low-privileged attacker read Kubernetes secrets across the cluster. The other seven, rated from 5.4 to 8.2, include a failure to check certificates that can expose array credentials to someone on the same network, and two cases of sensitive data being written to log files.
Why storage plug-ins matter
Any module that holds the administrator credentials for every storage array is an obvious target. Whoever controls it can reach the data on all of them. Dell has not flagged these flaws as exploited, but BleepingComputer notes that a suspected Chinese state-backed group exploited a maximum-severity hard-coded credential flaw in Dell's RecoverPoint for Virtual Machines from at least mid-2024, according to Mandiant and Google's threat intelligence group.