Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
{
"cpe": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.44"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.23"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.7"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23924.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"325384714460559008211380272189886777379",
"161202494417122568768003688957558185717",
"78613746942143536196276371120859374090",
"98679310835563898350721270856285671786",
"113434350780301213082882425875976030982",
"296560762299850979029643899112001044678"
],
"threshold": 0.9
},
"id": "CVE-2026-23924-234b3a70",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/b033beafb23d83ecb4e90a9b6f9ea856e9215566",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"284370360014678613696765199410977111724",
"46253585330142817602293402025070915692",
"324113470753803711083791540298503652665",
"76464632173684597398101110624076306055",
"1164161596515604490952627857606672780",
"129906473608321013084043110344064052208"
],
"threshold": 0.9
},
"id": "CVE-2026-23924-26d6ae0c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/f0d913a281292ea6bece7795c0d8e8cc611a74b3",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"240914845103889192647648019848926695597",
"30792924220085492397006343860712670132",
"95640358071569955326511545634389725735",
"90883749360215890357884073880131819361",
"99806028381006650636225484476175194516",
"28622387876498899219295977742604122279"
],
"threshold": 0.9
},
"id": "CVE-2026-23924-94d0e380",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/f4175e9b3ce144675906e9b8d8680bfbdb9c1053",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-20T14:24:12Z"