


Perceptive Security
SOC/SIEM Consultancy

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy.
This issue affects Apache Lucy: all versions.
As this project …
Published:
5 August 2026 at 00:00:00
Alert date:
5 August 2026 at 18:01:14
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
CVE-2026-61484 describes a Deserialization of Untrusted Data vulnerability affecting all versions of Apache Lucy. The Apache Lucy project has been retired and no patch or fix will be released. Users are advised to migrate to an alternative solution or restrict access to trusted users only. This vulnerability is notable because it affects an end-of-life product with no maintainer support. The risk is elevated for any organization still running Apache Lucy in internet-facing or multi-user environments. The advisory was published via the NVD and the Apache mailing list. Deserialization vulnerabilities can potentially allow remote code execution if untrusted data is processed. The lack of a fix makes mitigation through access control or migration the only viable options.
Technical details
Mitigation steps:
Affected products:
Apache Lucy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-61484
https://lists.apache.org/thread/942t3pwgz2nrhnklrtyt5zr7g4wqc9cb
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
