Back

MEDIUM

Agent 2 Docker plugin arbitrary file read via Docker API injection

Published Mar 24, 2026

Description

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Mar 24, 2026
Updated Mar 25, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Analyzed
Modified Sep 18, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Zabbix
Published Mar 24, 2026
Updated Mar 25, 2026
Exploited since n/a
EUVD-2026-14958