Dozzle Log Viewer Vulnerability in Agent-Backed Shell Endpoints
CVE-2026-24740
8.7HIGH
What is CVE-2026-24740?
A security flaw in Dozzle, a real-time log viewer for Docker containers, allows users with restricted label filters to gain unauthorized access to interactive root shells in containers outside their defined scope. This vulnerability occurs when targeting container IDs directly, enabling potential attackers to interact with containers not meant for their access. The issue has been resolved in version 9.0.3, which includes essential patches to curb this security risk.
Affected Version(s)
dozzle < 9.0.3
