Cybersecurity 3 min read

Dell Fixed Two 10.0 Storage Flaws, and Its Own Old Guide Used 'supersecret' as a Signing Key

Thirteen flaws in Dell's Kubernetes storage add-on include one that hands attackers every array's admin credentials. Sites set up from the archived guide must change the secret, not just update.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 3 Oct 2026, 2:07 PM (SGT)
Share:
Close-up of the Dell EMC logo on the front grille of a server Close-up of the Dell EMC logo on the front grille of a server Photo by Rajvardhan Rahul on Pexels
Advertisement

3 OCT 2026 — Companies that run Kubernetes on Dell storage arrays often use Container Storage Modules, an open-source suite from Dell, to connect the two and control who can use which storage. On 1 October Dell published fixes for 13 flaws in that suite. Six are rated critical and two score the maximum 10. One stems from Dell's own documentation, which once showed administrators a signing secret that was simply "supersecret".

Dell says it is not aware of any exploitation. It tells customers to update to version 1.18.0 or later.

The worst of the flaws

The top-rated flaw, CVE-2026-63688 at 10.0, sits in the authorization module's storage service. Dell's advisory says an unauthenticated attacker over the network could obtain the administrator credentials for every storage array registered with it, a complete bypass of the module's security. A second 10.0, CVE-2026-63692, in the authorization proxy and tenant service, lets an unauthenticated attacker skip authentication and take administrative control.

Another, CVE-2026-67269 at 9.9, lets a low-privileged attacker gain root on cluster nodes. Dell says that could compromise every node in the Kubernetes cluster. A third, CVE-2026-54472 at 9.8, comes from hard-coded credentials that let an unauthenticated attacker forge valid administrator tokens.

13Flaws fixed in Dell Container Storage Modules on 1 October
2 at 10.0Flaws with the maximum severity score
"supersecret"The signing secret Dell's documentation once showed
1.18.0The version Dell says fixes the flaws

The documented secret

The most unusual entry, CVE-2026-61421 at 9.8, sits in karavi-authorization, an older component now archived and no longer maintained. Dell's advisory says the official configuration documentation "demonstrated supersecret as the JWT signing secret alongside real token output," and that the page "was subsequently removed without a security advisory."

Any organisation that set up karavi-authorization from that guide and never changed the secret "may remain vulnerable," Dell says. The secret was public, so an attacker could forge login tokens and gain administrative rights without credentials. Updating the software does not fix this one by itself. The secret has to be changed.

Advertisement

A familiar kind of flaw

Hard-coded and default credentials are a familiar problem in serious appliance flaws. This year, attackers went on to exploit a hard-coded password in Cisco's firewall manager.

The rest of the list

The sixth critical flaw, CVE-2026-67273 at 9.6, lets a low-privileged attacker read Kubernetes secrets across the cluster. The other seven, rated from 5.4 to 8.2, include a failure to check certificates that can expose array credentials to someone on the same network, and two cases of sensitive data being written to log files.

Why storage plug-ins matter

Any module that holds the administrator credentials for every storage array is an obvious target. Whoever controls it can reach the data on all of them. Dell has not flagged these flaws as exploited, but BleepingComputer notes that a suspected Chinese state-backed group exploited a maximum-severity hard-coded credential flaw in Dell's RecoverPoint for Virtual Machines from at least mid-2024, according to Mandiant and Google's threat intelligence group.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement