CVE-2026-61484
9.8 CRITICALPublished 2026-08-05 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw is a deserialization vulnerability in Apache Lucy, allowing untrusted data to be deserialized, which can lead to remote code execution or other severe impacts. This matters because it can enable attackers to exploit the software even though it is no longer supported.
- Exploitability
- Exploitation requires access to deserialize untrusted data, making it moderately difficult but still feasible with the right conditions.
- Blast radius
- If exploited, this could result in significant damage, including remote code execution and complete system compromise.
- Prioritized remediation
- Restrict access to instances of Apache Lucy to trusted users or migrate to an alternative solution.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Vendors
apache
Products
lucy
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.