Back to database
Soon55Critical10.0VulnerabilityCVE-2026-63688No patch link observed

CVE-2026-63688 — Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-a…

Published Oct 6, 2026, 03:17 PM UTCIngested 2d agoSource NVD(cve-db)CVE-2026-63688

Description

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
10.0

Critical severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Changed

Scope

C

High

Confidentiality

I

High

Integrity

A

High

Availability

Affected

Vendor
dell
Product
container storage modules

Versions

  • < 1.18.0

Stated as the source expressed them.