Dell CSM Critical Authorization and Kubernetes-Control Hunt

Threat Overview

Dell published DSA-2026-448 on October 1, 2026 for multiple vulnerabilities in Dell Container Storage Modules (CSM), which extend Kubernetes CSI drivers for PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. The most severe issues include two CVSS 10.0 missing-authentication flaws in CSM Authorization 2.4.0: CVE-2026-63688 can expose storage-backend administrator credentials for all registered arrays, and CVE-2026-63692 can grant complete administrative control of the authorization service across tenants.

The advisory also includes CVE-2026-67269 (CVSS 9.9), in which a low-privilege attacker can abuse the ContainerStorageModule custom-resource reconciler to obtain root on cluster nodes; CVE-2026-54472 and CVE-2026-61421 (CVSS 9.8), involving forgeable administrative JWTs; and CVE-2026-67273 (CVSS 9.6), which can provide cluster-wide read access to Kubernetes Secrets and permit cluster-scoped RBAC creation.

These are vendor-confirmed vulnerabilities, not a confirmed exploitation campaign. Dell’s product remediation table states that CSM versions prior to 1.17.0 are affected and 1.18.0 or later is remediated, while individual entries identify CSM Authorization 2.4.0 and CSM Operator/CSM 1.12.0. Because the table does not explain the 1.17.x gap and says the list may be updated, affected deployments should be validated against Dell’s current advisory and exact component versions rather than inferred.

References

Impacted Systems

  • Vendor/product: Dell Container Storage Modules (CSM) for Kubernetes/OpenShift with Dell PowerStore, PowerScale, PowerFlex, PowerMax, or Unity XT storage.
  • Components: CSM Authorization 2.4.0 (csm-authorization-storage gRPC server, authorization proxy, tenant service); CSM Operator/ContainerStorageModule reconciler 1.12.0; affected CSM 1.12.0 template processing; archived karavi-authorization; related CSI drivers.
  • Deployment/platform: Self-managed Kubernetes or Red Hat OpenShift clusters with Dell CSM/CSI components and connected enterprise storage arrays.
  • Prerequisites: CVE-2026-63688/63692/54472/61421 are remotely exploitable without authentication when the vulnerable service is network reachable or the published signing secret remains in use. CVE-2026-67269/67273 require low-privilege Kubernetes access.
  • Exposure: Reachable CSM Authorization gRPC/proxy/tenant services, permission to submit or alter ContainerStorageModule resources, or continued use of the documented supersecret JWT signing value.
  • Affected/fixed versions: Dell’s table lists versions before 1.17.0 as affected and 1.18.0 or later as remediated; no workaround is listed. The advisory does not clearly classify 1.17.x and may be updated.
  • Explicitly unaffected: Not established for 1.17.x in the cited advisory. CSM 1.18.0 or later is the confirmed remediated target.

Why this matters

The vulnerabilities bridge Kubernetes control, storage credentials, and multi-tenant authorization. Successful exploitation could expose every registered array’s administrative credentials, alter storage access, read cluster secrets, create cluster-wide RBAC, or obtain root across nodes. This creates a high-impact path from a network-reachable service or low-privilege cluster account to storage and cluster compromise.

Exploitation Status

No confirmed active exploitation in public reporting as of October 4, 2026. Dell describes potential attacker impact and urges prompt upgrade but does not state the flaws were exploited. No public exploit IOCs are cited here.

What this hunt looks for

Dell CSM and Authorization image versions, anonymous access paths, Kubernetes Secret reads, ContainerStorageModule changes, cluster-scoped RBAC creation, pod exec or attach activity, authorization-log anomalies, and privilege behavior on CSM nodes.

Required logs

KubePodInventory, KubeAudit or KubeAuditAdmin, ContainerLogV2, Microsoft Defender for Endpoint telemetry on Kubernetes nodes, and Dell storage-array or CSM Authorization audit logs. Kubernetes audit logs alone do not capture direct gRPC calls to CSM Authorization.

Hunt 1 — First-pass inventory of Dell CSM, Authorization, and karavi images

let lookback = 14d;
KubePodInventory
| where TimeGenerated >= ago(lookback)
| where ContainerImage has_any ("dellemc", "dell/csm", "csm-authorization", "karavi", "csi-powerstore", "csi-powermax", "csi-powerflex", "csi-powerscale", "csi-unity")
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Clusters=make_set(ClusterName, 10), Namespaces=make_set(Namespace, 20), Pods=make_set(PodName, 30), Nodes=make_set(Computer, 30) by ContainerImage, ContainerName
| order by LastSeen desc

Hunt 2 — CSM images with ambiguous or pre-remediation tags

let lookback = 14d;
KubePodInventory
| where TimeGenerated >= ago(lookback)
| where ContainerImage has_any ("csm", "karavi", "csi-powerstore", "csi-powermax", "csi-powerflex", "csi-powerscale", "csi-unity")
| extend ImageTag=extract(@":([^/@]+)$", 1, ContainerImage)
| where isempty(ImageTag) or ImageTag in~ ("latest", "stable") or ImageTag matches regex @"^v?1\.(?:[0-9]|1[0-7])(?:\.|$)" or ContainerImage has "authorization:v2.4.0"
| summarize LastSeen=max(TimeGenerated), Pods=make_set(PodName, 30), Nodes=make_set(Computer, 30) by ClusterName, Namespace, ContainerImage, ImageTag
| order by LastSeen desc

Hunt 3 — Anonymous or unauthenticated Kubernetes API activity involving CSM

let lookback = 30d;
union isfuzzy=true KubeAudit, KubeAuditAdmin
| where TimeGenerated >= ago(lookback)
| extend Uri=tostring(RequestUri), Actor=tostring(User.username), Groups=tostring(User.groups), Sources=tostring(SourceIps), StatusCode=toint(ResponseStatus.code)
| where Uri has_any ("containerstoragemodules", "csm-authorization", "karavi", "csi-powerstore", "csi-powermax", "csi-powerflex", "csi-powerscale", "csi-unity")
| where Actor =~ "system:anonymous" or Groups has "system:unauthenticated"
| project TimeGenerated, ClusterName, Actor, Groups, Sources, Verb, Uri, StatusCode, UserAgent
| order by TimeGenerated desc

Hunt 4 — Kubernetes Secret enumeration or reads near CSM namespaces

let lookback = 30d;
union isfuzzy=true KubeAudit, KubeAuditAdmin
| where TimeGenerated >= ago(lookback)
| extend Uri=tostring(RequestUri), Actor=tostring(User.username), Sources=tostring(SourceIps), StatusCode=toint(ResponseStatus.code)
| where Uri has "/api/v1/" and Uri has "/secrets"
| where Verb in~ ("get", "list", "watch") and StatusCode between (200 .. 299)
| where Uri has_any ("dell", "csm", "karavi") or Actor has_any ("csm", "karavi", "dell") or Actor !startswith "system:serviceaccount:"
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Reads=count(), Sources=make_set(Sources, 20), URIs=make_set(Uri, 20) by ClusterName, Actor, bin(TimeGenerated, 1h)
| order by FirstSeen desc

Hunt 5 — ContainerStorageModule custom-resource creation or modification

let lookback = 30d;
union isfuzzy=true KubeAudit, KubeAuditAdmin
| where TimeGenerated >= ago(lookback)
| extend Uri=tostring(RequestUri), Actor=tostring(User.username), Sources=tostring(SourceIps), StatusCode=toint(ResponseStatus.code), Body=tostring(RequestObject)
| where Uri has "containerstoragemodules" and Verb in~ ("create", "update", "patch")
| where StatusCode between (200 .. 299)
| project TimeGenerated, ClusterName, Actor, Sources, Verb, Uri, StatusCode, Body, UserAgent
| order by TimeGenerated desc

Hunt 6 — Cluster-scoped RBAC creation or binding changes

let lookback = 30d;
union isfuzzy=true KubeAudit, KubeAuditAdmin
| where TimeGenerated >= ago(lookback)
| extend Uri=tostring(RequestUri), Actor=tostring(User.username), Sources=tostring(SourceIps), StatusCode=toint(ResponseStatus.code), Body=tostring(RequestObject)
| where Uri has_any ("/clusterroles", "/clusterrolebindings") and Verb in~ ("create", "update", "patch")
| where StatusCode between (200 .. 299)
| where Body has_any ("csm", "karavi", "dell") or Actor has_any ("csm", "karavi", "dell")
| project TimeGenerated, ClusterName, Actor, Sources, Verb, Uri, StatusCode, Body, UserAgent
| order by TimeGenerated desc

Hunt 7 — Exec or attach activity against Dell CSM pods

let lookback = 30d;
union isfuzzy=true KubeAudit, KubeAuditAdmin
| where TimeGenerated >= ago(lookback)
| extend Uri=tostring(RequestUri), Actor=tostring(User.username), Sources=tostring(SourceIps), StatusCode=toint(ResponseStatus.code)
| where Uri has_any ("csm", "karavi", "csi-powerstore", "csi-powermax", "csi-powerflex", "csi-powerscale", "csi-unity")
| where Uri has_any ("/exec", "/attach", "/portforward")
| project TimeGenerated, ClusterName, Actor, Sources, Verb, Uri, StatusCode, UserAgent
| order by TimeGenerated desc

Hunt 8 — Authentication, JWT, secret, or tenant anomalies in CSM logs

let lookback = 30d;
ContainerLogV2
| where TimeGenerated >= ago(lookback)
| where PodName has_any ("csm", "karavi", "authorization") or ContainerName has_any ("csm", "karavi", "authorization")
| extend Message=tostring(LogMessage)
| where Message has_any ("unauthenticated", "authentication bypass", "invalid token", "JWT", "signing secret", "admin credential", "tenant", "permission denied", "forbidden")
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Events=count(), Samples=make_set(Message, 20) by Computer, PodName, ContainerName, LogSource
| order by FirstSeen desc

Hunt 9 — Shells or privilege tools on nodes hosting CSM components

let lookback = 30d;
let CsmNodes = toscalar(KubePodInventory
    | where TimeGenerated >= ago(7d)
    | where ContainerImage has_any ("dellemc", "dell/csm", "csm-authorization", "karavi")
    | summarize make_set(tolower(Computer)));
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where tolower(DeviceName) in~ (CsmNodes)
| where FileName in~ ("sh", "bash", "nsenter", "chroot", "mount", "chmod", "chown", "kubectl")
| where ProcessCommandLine has_any ("/host", "/rootfs", "privileged", "cluster-admin", "serviceaccount", "/var/lib/kubelet") or InitiatingProcessCommandLine has_any ("csm", "karavi", "dell")
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
| order by Timestamp desc

Detection Notes

  • Hunt 1 is the highest-value first pass. Image names and tags vary by registry and installation method; verify digests and Helm/operator release metadata rather than relying only on tag text.
  • Hunt 2 is triage, not a definitive version test. Dell’s advisory has a version-table ambiguity around 1.17.x; 1.18.0 or later is the confirmed remediated target.
  • Kubernetes audit logs do not record direct gRPC calls to the CSM Authorization service. Network or application logs for that service are required to see CVE-2026-63688/63692 exploitation attempts.
  • Secret reads, RBAC changes, custom-resource edits, and pod exec sessions can be legitimate administrator/operator behavior. Prioritize new actors, unexpected source IPs, unusual user agents, changes outside deployment windows, and sequences spanning multiple categories.
  • Hunt 8 depends on what the component logs; the listed strings are behavioral pivots, not vendor-published exploit indicators.
  • Node endpoint telemetry may not preserve pod/container attribution. Correlate node and pod placement at the event time.
  • Without KubePodInventory, KubeAudit/KubeAuditAdmin, ContainerLogV2, storage-array audit logs, and node endpoint telemetry, critical portions of this threat will not be visible in Sentinel.