CVE-2026-70411
Received Received - Intake

Missing Authentication in Dell CSM Prior to 1.18.0

Vulnerability report for CVE-2026-70411, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: Dell

Description

Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Dell Container Storage Modules (CSM) 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dell Container Storage Modules (CSM) before version 1.18.0 has a vulnerability where the csm-authorization-tenant gRPC service lacks authentication. An attacker on the same network could exploit this to create unauthorized tenant entities, inject cross-tenant roles, and modify storage access controls without authentication.

Detection Guidance

Detecting this vulnerability requires checking for exposed gRPC services, specifically the csm-authorization-tenant service, on your network. Use network scanning tools like nmap to identify open ports and services. Look for unauthenticated access to the TenantService endpoint. Example command: nmap -p 50051 <target_IP> --script grpc-info.

Impact Analysis

This vulnerability could allow unauthorized users to create fake tenant accounts, escalate privileges across tenants, and change storage permissions. This may lead to data breaches, unauthorized access to sensitive information, or disruption of storage services.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR (data protection) and HIPAA (health data security) by enabling unauthorized access to sensitive data. Organizations may face legal penalties, loss of certification, or reputational damage due to non-compliance.

Mitigation Strategies

Immediately upgrade Dell CSM to version 1.18.0 or later to address the missing authentication flaw. Ensure the csm-authorization-tenant gRPC service is not exposed to adjacent networks. Restrict network access using firewalls and disable unnecessary services. Monitor for unauthorized tenant creation or role changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70411. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart