#VU124620 Relative Path Traversal in Zabbix - CVE-2026-23924
Published: March 25, 2026
Zabbix
Zabbix
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in the Agent 2 Docker plugin when handling requests with the 'docker.container_info' parameter. A remote user can send a specially crafted request to read arbitrary files from running Docker containers via Docker API injection.
Successful exploitation requires the attacker to have valid credentials and access to invoke Agent 2 commands.