Vulnerability Intelligence Report
CVE-2026-67270
Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.
No Active Exploit Signals
CVSS Base Score
8.2
HIGH
Exploitability:1.7
Impact Score:6.0
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-295 ↗CWE-295: Improper Certificate Validation
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Dell | Container Storage Modules (CSM) | 0 < 1.18.0 or later (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Dell · Vendor · USA |
| Reserved | 2026-07-29T11:04:32 |
| Published | 2026-10-06T15:06:09 |
| Patch Date | 2026-10-01 |
| Last Updated | 2026-10-06T15:06:09 |
Community Chatter & Buzz