CVE-2026-102413

Summary

Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists.

Affected Software

VendorProductVersion RangeStatus
ElasticElastic Agent and Elastic Defend8.19.13 <= 8.19.21affected
ElasticElastic Agent and Elastic Defend9.2.7 <= 9.2.8affected
ElasticElastic Agent and Elastic Defend9.3.0 <= 9.3.8affected
ElasticElastic Agent and Elastic Defend9.4.0 <= 9.4.7affected
ElasticElastic Agent and Elastic Defend9.5.0 <= 9.5.4affected

Weaknesses

  • CWE-248: CWE-248 Uncaught Exception

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References