← Back to search

CVE-2026-61484

9.8 CRITICAL

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw is a deserialization vulnerability in Apache Lucy, allowing untrusted data to be deserialized, which can lead to remote code execution or other severe impacts. This matters because it can enable attackers to exploit the software even though it is no longer supported.
Exploitability
Exploitation requires access to deserialize untrusted data, making it moderately difficult but still feasible with the right conditions.
Blast radius
If exploited, this could result in significant damage, including remote code execution and complete system compromise.
Prioritized remediation
Restrict access to instances of Apache Lucy to trusted users or migrate to an alternative solution.
rcedeserializationlegacy

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Vendors

apache

Products

lucy

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.