CVE-2026-70411
HIGH
NVD
CVSS Score
7.1
Severity
HIGH
Published
Oct 06, 2026
Vendor
unknown
Description
Dell Container Storage Modules (CSM), versions prior to 1.18.0, contains a Missing Authentication for Critical Function vulnerability in the csm-authorization-tenant gRPC service (TenantService). An unauthenticated adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized creation of tenant entities, cross-tenant role injection, and modification of storage access control flags.