CVE-2026-23924
EUVD-2026-1495824.03.2026, 19:16
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.43 |
| zabbix | zabbix | 7.0.0 ≤ 𝑥 ≤ 7.0.22 |
| zabbix | zabbix | 7.4.0 ≤ 𝑥 ≤ 7.4.6 |
𝑥
= Vulnerable software versions