# Elastic Agent / Endpoint 8.19.22, 9.4.8, and 9.5.5 Security Update (ESA-2026-194)

**URL:** <https://discuss.elastic.co/t/elastic-agent-endpoint-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-194/390868>\
**Category:** Security Announcements\
**Created:** [October 6, 2026, 6:47pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-194/390868 "2026-10-06T18:47:56Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [October 6, 2026, 6:47pm UTC](https://discuss.elastic.co/t/elastic-agent-endpoint-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-194/390868/1 "2026-10-06T18:47:56Z")

</div>

**Uncaught Exception in Elastic Endpoint Leading to Denial of Service**

Uncaught Exception (CWE-248) in Elastic Endpoint can lead to denial of service via a specially crafted file name. When Elastic Defend's Elastic Endpoint component processes a file name under certain system locale configurations (including Chinese, Japanese, and Korean locales) on Windows, an unhandled exception can occur during file-path handling. This causes the Elastic Endpoint process to crash and restart repeatedly, which can degrade or disable Elastic Defend's real-time malware prevention and behavioral detection capabilities on the affected host for as long as the condition persists.

**Affected Versions:**

> - 8.x: All versions from 8.19.13 up to and including 8.19.21
> - 9.x:

- All versions from 9.2.7 up to and including 9.2.8
- All versions from 9.3.0 up to and including 9.3.8
- All versions from 9.4.0 up to and including 9.4.7
- All versions from 9.5.0 up to and including 9.5.4

Elastic Agent / Endpoint versions prior to 8.19.13 on the 8.19.x line, and prior to 9.2.7 on the 9.2.x line, are not affected by this issue.

No fix is available for the 9.2.x or 9.3.x lines; users on these lines should upgrade to a supported release line.

**Affected Configurations:**

> - Hosts running with certain Windows system locales (including Chinese, Japanese, and Korean) are affected; hosts running other locales are not affected.

**Solutions and Mitigations:**

This issue is resolved in Elastic Agent / Endpoint 8.19.22, 9.4.8, and 9.5.5.

Elastic recommends upgrading to the most recent release available, and reviewing the known issues for your target version before upgrading.

**For Users that Cannot Upgrade:**

> - There are no workarounds for this vulnerability.

**Indicators of Compromise (IOC)**

No specific indicators of compromise have been identified for this vulnerability.

**Severity:** CVSSv3.1: Medium ( 6.2 ) - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H  
**CVE ID:** CVE-2026-102413  
**Problem Type:** CWE-248 - Uncaught Exception
