Dell CSM Proxy-Server Improper Cert Validation before v1.18.0
CVE-2026-67270 Published on October 6, 2026
Dell Container Storage Modules (CSM) versions prior to 1.18.0, contains an Improper Certificate Validation vulnerability in the proxy-server component. An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to information exposure of storage backend administrator credentials.
Vulnerability Analysis
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-67270
Want to know whenever a new CVE is published for Dell Container Storage Modules? stack.watch will email you.
Affected Versions
Dell Container Storage Modules (CSM):- Before 1.18.0 or later is affected.