MEDIUM
Agent 2 Docker plugin arbitrary file read via Docker API injection
Published Mar 24, 2026
6.1
MEDIUMCVSS 4.0
EPSS 0.23%
Description
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
Affected products
-
- Version 6.0.0StatusaffectedConstraints<=6.0.43
- Version 7.0.0StatusaffectedConstraints<=7.0.22
- Version 7.4.0StatusaffectedConstraints<=7.4.6
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update the affected components to their respective fixed versions.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14958 Advisory
- https://support.zabbix.com/browse/ZBX-27642 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14958 | Advisory | |
| https://support.zabbix.com/browse/ZBX-27642 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Mar 24, 2026
Updated Mar 25, 2026
Reserved Jan 19, 2026
Link CVE-2026-23924
CISA Vulnrichment
Updated Mar 25, 2026
ENISA EUVD
EUVD-2026-14958 Assigner Zabbix
Published Mar 24, 2026
Updated Mar 25, 2026
Exploited since n/a
Link EUVD-2026-14958