CVE-2026-23924: Zabbix

Medium severity, CVSS 4.9. EPSS: 0.2% chance of exploitation in the next 30 days.

Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.44 (fixed in 6.0.44); from 7.0.0, before 7.0.23 (fixed in 7.0.23); from 7.4.0, before 7.4.7 (fixed in 7.4.7)

Published 2026-03-24. Last modified 2026-09-18.