Dozzle Log Viewer Vulnerability in Agent-Backed Shell Endpoints
CVE-2026-24740

8.7HIGH

Key Information:

Vendor

Amir20

Status
Vendor
CVE Published:
27 January 2026

What is CVE-2026-24740?

A security flaw in Dozzle, a real-time log viewer for Docker containers, allows users with restricted label filters to gain unauthorized access to interactive root shells in containers outside their defined scope. This vulnerability occurs when targeting container IDs directly, enabling potential attackers to interact with containers not meant for their access. The issue has been resolved in version 9.0.3, which includes essential patches to curb this security risk.

Affected Version(s)

dozzle < 9.0.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.