CVE-2026-23924

Source
https://cve.org/CVERecord?id=CVE-2026-23924
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23924.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23924
Downstream
Published
2026-03-24T19:16:50Z
Modified
2026-09-20T14:24:12Z
Severity
  • 4.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

References

Affected packages

Git / github.com/zabbix/zabbix

Affected ranges

Type
GIT
Repo
https://github.com/zabbix/zabbix
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.0.44"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.23"
        },
        {
            "introduced": "7.4.0"
        },
        {
            "fixed": "7.4.7"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

6.*
6.0.0
6.0.1
6.0.10
6.0.10rc1
6.0.10rc2
6.0.11
6.0.11rc1
6.0.11rc2
6.0.12
6.0.12rc1
6.0.12rc2
6.0.13
6.0.13rc1
6.0.14
6.0.14rc1
6.0.14rc2
6.0.15
6.0.15rc1
6.0.15rc2
6.0.16
6.0.16rc1
6.0.17
6.0.17rc1
6.0.17rc2
6.0.18
6.0.18rc1
6.0.19
6.0.19rc1
6.0.1rc1
6.0.1rc2
6.0.1rc3
6.0.1rc4
6.0.2
6.0.20
6.0.20rc1
6.0.21
6.0.21rc1
6.0.22
6.0.22rc1
6.0.23
6.0.23rc1
6.0.25
6.0.25rc1
6.0.26
6.0.26rc1
6.0.27
6.0.27rc1
6.0.28
6.0.28rc1
6.0.29
6.0.29rc1
6.0.2rc1
6.0.3
6.0.30
6.0.30rc1
6.0.31
6.0.31rc1
6.0.32
6.0.32rc1
6.0.33
6.0.33rc1
6.0.34
6.0.34rc1
6.0.34rc2
6.0.35
6.0.35rc1
6.0.36
6.0.36rc1
6.0.37
6.0.37rc1
6.0.38
6.0.38rc1
6.0.39
6.0.39rc1
6.0.3rc1
6.0.4
6.0.40
6.0.40rc1
6.0.41
6.0.41rc1
6.0.42
6.0.42rc1
6.0.43
6.0.43rc1
6.0.44rc1
6.0.4rc1
6.0.5
6.0.5rc1
6.0.6
6.0.6rc1
6.0.7
6.0.7rc1
6.0.8
6.0.8rc1
6.0.8rc2
6.0.9
6.0.9rc1
6.0.9rc2
7.*
7.0.0
7.0.1
7.0.10
7.0.10rc1
7.0.11
7.0.11rc1
7.0.11rc2
7.0.12
7.0.12rc1
7.0.13
7.0.13rc1
7.0.14
7.0.14rc1
7.0.15
7.0.16
7.0.17
7.0.17rc1
7.0.17rc2
7.0.18
7.0.18rc1
7.0.18rc2
7.0.19
7.0.19rc1
7.0.1rc1
7.0.1rc2
7.0.2
7.0.20
7.0.20rc1
7.0.21
7.0.22
7.0.22rc1
7.0.22rc2
7.0.22rc3
7.0.23rc1
7.0.23rc2
7.0.2rc1
7.0.2rc2
7.0.3
7.0.3rc1
7.0.4
7.0.4rc1
7.0.5
7.0.5rc1
7.0.6
7.0.6rc1
7.0.7
7.0.7rc1
7.0.8
7.0.8rc1
7.0.8rc2
7.0.9
7.0.9rc1
7.0.9rc2
7.4.0
7.4.1
7.4.1rc1
7.4.2
7.4.2rc1
7.4.2rc2
7.4.3
7.4.3rc1
7.4.4
7.4.4rc1
7.4.5
7.4.6
7.4.6rc1
7.4.6rc2
7.4.7rc1
7.4.7rc2
7.4.7rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23924.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "325384714460559008211380272189886777379",
                "161202494417122568768003688957558185717",
                "78613746942143536196276371120859374090",
                "98679310835563898350721270856285671786",
                "113434350780301213082882425875976030982",
                "296560762299850979029643899112001044678"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-23924-234b3a70",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zabbix/zabbix/commit/b033beafb23d83ecb4e90a9b6f9ea856e9215566",
        "target": {
            "file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "284370360014678613696765199410977111724",
                "46253585330142817602293402025070915692",
                "324113470753803711083791540298503652665",
                "76464632173684597398101110624076306055",
                "1164161596515604490952627857606672780",
                "129906473608321013084043110344064052208"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-23924-26d6ae0c",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zabbix/zabbix/commit/f0d913a281292ea6bece7795c0d8e8cc611a74b3",
        "target": {
            "file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "240914845103889192647648019848926695597",
                "30792924220085492397006343860712670132",
                "95640358071569955326511545634389725735",
                "90883749360215890357884073880131819361",
                "99806028381006650636225484476175194516",
                "28622387876498899219295977742604122279"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-23924-94d0e380",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/zabbix/zabbix/commit/f4175e9b3ce144675906e9b8d8680bfbdb9c1053",
        "target": {
            "file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:24:12Z"