CVE-2026-23924: Agent 2 Docker plugin arbitrary file read via Docker API injection
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.containerinfo' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23924?
CVE-2026-23924 is categorized as a high severity vulnerability due to its potential for arbitrary file read access.
How can I mitigate CVE-2026-23924?
To mitigate CVE-2026-23924, ensure that the Zabbix Agent 2 Docker plugin is updated to the latest version that addresses this vulnerability.
What are the potential impacts of CVE-2026-23924?
The potential impacts of CVE-2026-23924 include unauthorized access to sensitive files within Docker containers, which could lead to data breaches.
Who is affected by CVE-2026-23924?
CVE-2026-23924 affects users of the Zabbix Agent 2 Docker plugin that do not implement proper sanitization of parameters.
Is authentication required to exploit CVE-2026-23924?
No, an attacker capable of invoking Agent 2 can exploit CVE-2026-23924 without needing authentication.