LIVE · cybersecurity feed
Live wire
cve record

CVE-2026-23924

Published
CVSS—
Severitynone
WeaknessCWE-88
ExploitedNot in CISA KEV

Description

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-23924

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-23924.