Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://support.zabbix.com/browse/ZBX-27642 |
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-24 19:16
Updated : 2026-03-25 15:41
NVD link : CVE-2026-23924
Mitre link : CVE-2026-23924
CVE.ORG link : CVE-2026-23924
JSON object : View
Products Affected
No product.
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
