Description
Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized tenant creation and privilege escalation
Action: Immediate Patch
AI Analysis

Impact

Dell Container Storage Modules before version 1.18.0 are affected by a missing authentication flaw in the TenantService gRPC endpoint. The vulnerability allows an attacker with network proximity to create arbitrary tenant entities, inject cross‑tenant roles, and alter storage access control flags without any credentials, giving them unauthorized control over the storage platform.

Affected Systems

The affected products are Dell Container Storage Modules (CSM) running version 1.17.x and earlier.

Risk and Exploitability

The flaw scores a 7.1 on CVSS, indicating a high impact. EPSS is not available, but the vulnerability is not listed in CISA KEV. The attack vector is likely an unauthenticated adversary on an adjacent or otherwise trusted local network that can reach the gRPC service, making exploitation feasible without initial compromise.

Generated by OpenCVE AI on October 6, 2026 at 18:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dell Container Storage Modules to version 1.18.0 or higher to apply the official fix for the missing authentication issue.
  • Configure firewall or network segmentation rules to restrict access to the CSM gRPC interface to approved administrative hosts only.
  • Implement monitoring on the container storage modules to detect unauthorized tenant creation or role modification events, and enforce logging for all critical actions.

Generated by OpenCVE AI on October 6, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Tenant Creation and Privilege Escalation via Missing Authentication in Dell Container Storage Modules

Tue, 06 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Description Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-10-06T15:17:21.207Z

Reserved: 2026-08-04T11:16:10.498Z

Link: CVE-2026-70411

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T16:17:09.877

Modified: 2026-10-06T16:17:09.877

Link: CVE-2026-70411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T18:15:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function