CVE-2026-63688
container_storage_modules: Missing Authentication for Critical Function (CVE-2026-63688)
Description
Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.18.0fixed from 1.18.0Metrics
Show all metrics
Weakness classes (CWE)
CWE-306Base
Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-10-08 14:15 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:dell:container_storage_modules:*:*:*:*:*:*:*:* versions up to (excluding) 1.18.0
- Reference Type: Dell: https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 Types: Vendor Advisory
- CVE Modified2026-10-06 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-63688","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-10-06 15:17 UTC· security_alert@emc.com
- Description: Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-306
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/63xxx/CVE-2026-63688.json">CVE-2026-63688</a>