CVE-2026-70411: Dell Container Storage Modules Csm

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.

Affected products

  • Dell Container Storage Modules Csm

Published 2026-10-06. Last modified 2026-10-08.