Description
Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists.
Published: 2026-10-06
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

An unhandled exception occurs in Elastic Endpoint’s file‑path handling routine when a specially crafted file name is processed under certain system locale settings, such as Chinese, Japanese, and Korean locales on Windows. The exception is not caught and causes the Elastic Endpoint process to crash and restart repeatedly. This brings down the real‑time malware prevention and behavioral detection functions on the host, which can be sustained for as long as the offending condition persists, effectively disrupting security controls.

Affected Systems

The flaw affects Elastic’s Elastic Agent and Elastic Defend products. It is observed on Windows environments where the system locale is set to Chinese, Japanese, or Korean. Exact version details are not supplied in the advisory, but the issue was identified in the context of recent releases of Elastic Endpoint.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.2, indicating moderate severity. Because EPSS data is unavailable, the current exploitation likelihood cannot be quantified, and the issue is not listed in CISA KEV. An attacker can trigger the denial of service by delivering a file name that triggers the exception, typically by placing a malicious artifact on the host or instructing the local endpoint to process a crafted filename. The impact is isolated to the local host that runs the Elastic Endpoint component, but in a network where multiple host agents rely on Elastic Defend, the outage could propagate indirect availability problems.

Generated by OpenCVE AI on October 6, 2026 at 20:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Elastic Security update that patches the file‑name handling logic in Elastic Endpoint
  • Configure host systems to avoid Chinese, Japanese, or Korean locale options when running Elastic Endpoint, or ensure locale is set to an English‑based locale
  • Enable monitoring of the Elastic Endpoint process to detect repeated crashes or restarts and trigger automated remediation or fail‑over processes

Generated by OpenCVE AI on October 6, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists.
Title Uncaught Exception in Elastic Endpoint Leading to Denial of Service
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-10-06T19:54:08.886Z

Reserved: 2026-09-29T02:06:02.426Z

Link: CVE-2026-102413

cve-icon Vulnrichment

Updated: 2026-10-06T19:54:04.515Z

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:13.463

Modified: 2026-10-06T20:17:13.463

Link: CVE-2026-102413

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:45:06Z

Weaknesses