CVE-2026-40711
Dell · Container Storage Modules (CSI PowerStore)
A security vulnerability exists in Dell Container Storage Modules (CSI PowerStore) version 2, potentially impacting the integrity of storage management operations.
Executive summary
A high-severity vulnerability in Dell Container Storage Modules (CSI PowerStore) could allow an attacker to compromise storage infrastructure integrity.
Vulnerability
This vulnerability affects the CSI PowerStore driver within Dell's Container Storage Modules. Detailed technical specifics are limited, but the flaw likely allows for unauthorized manipulation or access to storage resources via the container orchestration interface.
Business impact
With a CVSS score of 8.0, this vulnerability presents a significant risk to data availability and storage security. Successful exploitation could lead to unauthorized access to persistent storage volumes or disruption of mission-critical containerized services, resulting in operational downtime.
Remediation
Immediate Action: Apply the latest vendor security patches for Dell Container Storage Modules and the associated CSI PowerStore driver.
Proactive Monitoring: Audit container orchestration logs (e.g., Kubernetes API server logs) for unauthorized modifications to storage classes or persistent volume claims.
Compensating Controls: Utilize network segmentation to restrict access to the storage management interface to authorized administrative nodes only.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Security teams should treat this vulnerability with high priority, as it impacts core storage infrastructure. Ensure that all CSI drivers are updated to the latest secure versions to maintain the confidentiality and integrity of your containerized data environment.