CVE-2026-63688

container_storage_modules: Missing Authentication for Critical Function (CVE-2026-63688)

criticalEPSS 0.8%

Description

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

dellcontainer_storage_modules
1.18.0fixed from 1.18.0

Metrics

10.0
Source: cna-v3
55.0 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-06 15:17 UTC
CWE-306

Weakness classes (CWE)

  • CWE-306Base

    Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-10-08 14:15 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:dell:container_storage_modules:*:*:*:*:*:*:*:* versions up to (excluding) 1.18.0
    • Reference Type: Dell: https://www.dell.com/support/kbdoc/en-us/000515771/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9 Types: Vendor Advisory
  2. CVE Modified2026-10-06 18:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-63688","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  3. New CVE Received2026-10-06 15:17 UTC· security_alert@emc.com
    • Description: Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-storage gRPC server. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to unauthorized access to storage backend administrator credentials for all registered storage arrays.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    • CWE: CWE-306
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/63xxx/CVE-2026-63688.json">CVE-2026-63688</a>

Linked advisories