Description
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Published: 2026-10-06
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Dell Container Storage Modules prior to version 1.18.0 embed hard‑coded credentials in their authorization component. An unauthenticated network user can exploit this flaw to authenticate as an administrator, thereby gaining full control of the system. The vulnerability directly undermines confidentiality and integrity and allows arbitrary privileged actions, including the execution of commands that could compromise the entire storage environment.

Affected Systems

Dell Container Storage Modules (CSM) versions earlier than 1.18.0 are affected. The flaw resides in the CSM authorization layer and has not been addressed in any prior releases.

Risk and Exploitability

The CVSS score of 9.8 denotes a critical risk level. EPSS data is unavailable, but the lack of a KEV listing suggests no widespread exploitation has been reported yet. Based on the description, it is inferred that an attacker only needs remote, unauthenticated access to the CSM interface to exploit the hard‑coded credentials and elevate privileges. If successful, the attacker can assume administrator rights, compromising the entire container storage environment.

Generated by OpenCVE AI on October 6, 2026 at 18:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download the Dell Container Storage Modules update 1.18.0 or newer from Dell’s support site and apply it to the affected systems.
  • Restart the CSM services to ensure the updated configuration takes effect.
  • Replace any remaining default or hard‑coded credentials with unique, strong passwords and verify that authentication settings comply with secure‑auth best practices.

Generated by OpenCVE AI on October 6, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell container Storage Modules
Vendors & Products Dell
Dell container Storage Modules

Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Title Hard‑coded Credentials in Dell CSM Authorization Allow Remote Privilege Escalation

Tue, 06 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Use of Hard-coded Credentials vulnerability in the CSM Authorization. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dell Container Storage Modules
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-06T15:25:08.047Z

Reserved: 2026-07-09T11:05:01.707Z

Link: CVE-2026-61421

cve-icon Vulnrichment

Updated: 2026-10-06T15:24:19.983Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T15:17:18.767

Modified: 2026-10-06T16:17:08.830

Link: CVE-2026-61421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:45:12Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials