← Back to search

CVE-2026-61486

9.8 CRITICAL

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
A stack-based buffer overflow vulnerability exists in Apache Lucy, which could lead to remote code execution if exploited.
Exploitability
Exploitation is difficult due to the need for precise control over the buffer, but preconditions include the presence of untrusted input.
Blast radius
If exploited, this could result in complete control over the affected system, leading to potential data loss or system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Restrict access to the instance to trusted users and disable the affected feature if possible.
rcebuffer-overflowwebapache

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-121

Vendors

apache

Products

lucy

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.