← Back to search

CVE-2026-61484

9.8 CRITICAL

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw is a deserialization vulnerability in Apache Lucy, allowing attackers to execute arbitrary code. This matters because it can lead to complete system compromise.
Exploitability
Exploitation is relatively easy given the deserialization vulnerability, requiring only that untrusted data be processed.
Blast radius
If exploited, this could result in complete system compromise and data loss.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the affected feature or restrict access to the instance to trusted users.
rcedeserializationwebapache

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Vendors

apache

Products

lucy

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.