Dell CSM Critical Flaws Allow Root on Kubernetes Nodes
Dell patches multiple critical flaws in Container Storage Modules that allow unauthenticated attackers to gain admin access and root on Kubernetes nodes.

Dell released patches this week for multiple critical vulnerabilities in Dell Container Storage Modules (CSM), its open-source Kubernetes storage plugin collection. The vulnerabilities allow unauthenticated attackers to gain administrative access to affected Kubernetes clusters and root-level execution on the underlying nodes.
That scope is worth pausing on. A storage plugin isn’t usually where cluster administrators think about their attack surface. CSM runs as a privileged Kubernetes component to provision volumes and manage connections to Dell storage backends. That operating level means a critical authentication bypass in CSM isn’t a path to one container or one pod: it’s a path to the nodes themselves.
What was patched
Dell disclosed the vulnerabilities alongside reporting by The Hacker News. Specific CVE identifiers and affected version ranges are in Dell’s security advisory portal. Dell had not confirmed active exploitation as of this writing.
The affected product is Dell CSM, which provides Kubernetes storage integrations for multiple Dell storage arrays. Organizations running CSM in production should apply the patched version as described in Dell’s advisory.
The broader pattern
Kubernetes storage plugins have been a consistent soft spot in cluster security this year. They need elevated permissions to do their job: provisioning PersistentVolumes, binding PersistentVolumeClaims, managing backend storage credentials. Kubernetes clusters often extend these permissions broadly, because storage just works once configured and no one revisits it.
That makes them a useful pivot point. In September, a flaw in kcp’s front-proxy authentication let attackers impersonate arbitrary users across cluster boundaries. The JADEPUFFER cluster used stolen Azure service principals to trigger resource deletion across entire Azure tenants. The infrastructure layer, the plumbing that makes Kubernetes work, is the attack surface that doesn’t show up on most threat models because it’s presumed internal.
Dell CSM running with a critical authentication bypass on a Kubernetes node is the same problem in a different package.
What to do
Apply Dell’s patched CSM version as described in the advisory. If immediate patching isn’t possible, restrict network access to CSM management interfaces and audit the service account permissions granted to CSM components.
After patching, review your cluster for unexpected admin role bindings and unexplained PersistentVolume claims created before the patch was applied. A patch closes the hole; a log review tells you whether it was open long enough to matter.
Found this useful? Share it.


