Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists. | |
| Title | Uncaught Exception in Elastic Endpoint Leading to Denial of Service | |
| Weaknesses | CWE-248 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: elastic
Published:
Updated: 2026-10-06T19:54:08.886Z
Reserved: 2026-09-29T02:06:02.426Z
Link: CVE-2026-102413
Updated: 2026-10-06T19:54:04.515Z
Status : Received
Published: 2026-10-06T20:17:13.463
Modified: 2026-10-06T20:17:13.463
Link: CVE-2026-102413
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:45:06Z
-
CWE-248
Uncaught Exception