CVE 6.1 MEDIUM

Agent 2 Docker plugin arbitrary file read via Docker API injection_CVE-2026-23924

6.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

Description

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

Basic Information

ID CVE-2026-23924
Source Zabbix
Published Mar 24, 2026 at 18:30
Modified Mar 25, 2026 at 19:25

Affected Product

Vendor Zabbix
Product Zabbix
Version 6.0.0
Affected Versions Zabbix Zabbix 6.0.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.