CVE-2026-70411

Summary

Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.

Affected Software

VendorProductVersion RangeStatus
DellContainer Storage Modules (CSM)0 < 1.18.0 or lateraffected

Weaknesses

  • CWE-306: CWE-306: Missing Authentication for Critical Function

References