Back to News

LibreOffice Calc, Apache OpenOffice Calc Flaws Enable Java Code Execution: CVE-2026-63277, CVE-2026-59265

LibreOffice Calc, Apache OpenOffice Calc Flaws Enable Java Code Execution: CVE-2026-63277, CVE-2026-59265

Vulnerabilities in LibreOffice Calc and Apache OpenOffice Calc can execute attacker-supplied Java code when a crafted spreadsheet is opened, without the macro-style warning or active-content prompt normally shown for macros. The Document Foundation released LibreOffice fixes on October 5, 2026, while Apache OpenOffice 4.1.16 and earlier remained affected pending version 4.1.17. Public proof-of-concept files and technical write-ups are available, although no exploitation in the wild had been confirmed at the time of reporting.

Key Points

  • LibreOffice users should upgrade to version 26.2.5 or 26.8.0.
  • Apache OpenOffice 4.1.16 and earlier are affected, with a fix expected in version 4.1.17.
  • The attack requires Java and JDBC support to be installed and enabled in the office application.
  • Researchers have published proof-of-concept files, increasing the risk of reuse by attackers.

How the spreadsheet attack works

The attack uses Calc’s database range feature, which can refresh data through an external database link. A crafted spreadsheet can reference an ODB database file that names a Java database connectivity driver and points to a JAR file containing Java code hosted locally or on a remote server.

When the spreadsheet opens and the database range refreshes, LibreOffice or OpenOffice can download the ODB file, download the JAR file, and start the JDBC driver. This causes the attacker’s Java code to run inside the office application process. The attack requires a Java runtime environment and JDBC support to be installed and enabled; disabling Java blocks the main code-execution path tracked as CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice.

Researchers demonstrated the technique on Windows and Linux, showing that it is not limited to one operating system. The proof-of-concept code launched Calculator as a harmless demonstration, but the same execution path can run arbitrary Java code selected by an attacker.

The proof-of-concept files were placed locally for convenience. A real attack could host the ODB and JAR files on attacker-controlled servers, according to the technical findings.

The V12 security team described the result in its write-up:

“The attack runs the attacker’s code ‘without a macro-style safety warning or active-content prompt.’”

V12 security team

Vulnerabilities and affected versions

LibreOffice tracks the primary Calc code-execution issue as CVE-2026-63277, with a reported CVSS v4 score of 8.5, rated High. The Document Foundation released fixes on October 5, 2026, and recommends upgrading to LibreOffice 26.2.5 or 26.8.0. Caolán McNamara of Collabora Productivity wrote the LibreOffice fix.

The same LibreOffice update batch includes five related issues. CVE-2026-63266 allows arbitrary file writes through an embedded Firebird database, limited to locations where the user can write. CVE-2026-63267 and CVE-2026-63268 involve local file reads and SSRF-style behavior, including pulling local files into a spreadsheet and, in one case, making requests to a host selected by the document.

CVE-2026-63269 affects Linux systems and allows linked media handled through GStreamer to follow HLS playlists to local files and remote URLs. CVE-2026-63270 allows crafted links to expand environment variables or INI file values, potentially exposing the resulting data. The other five LibreOffice vulnerabilities were rated Medium, with reported CVSS scores of approximately 6.7 or 6.8.

Apache OpenOffice tracks the corresponding Java integration flaw as CVE-2026-59265. The issue affects Apache OpenOffice 4.1.16 and earlier, while the fix was expected in version 4.1.17, which was in release-candidate testing at the time of reporting.

Public research and mitigation

Rick de Jager of the V12 security team, along with Thomas Rinsma and Edoardo Geraci of Codean Labs, published proof-of-concept files and technical write-ups around the disclosure. Public alerts and summaries appeared on October 6, 2026. No confirmed in-the-wild exploitation had been identified at that point.

Apache OpenOffice recommends disabling Java until version 4.1.17 is available. Users can do this through Tools > Options > OpenOffice > Java by clearing the “Use a Java runtime environment” setting.

Users of both office suites should avoid opening spreadsheets from untrusted sources and disable Java support when it is not required. LibreOffice users should apply version 26.2.5 or 26.8.0, while Apache OpenOffice users should keep Java disabled until the fixed release is installed.

Sources

Mayank Mehra

Written by

Mayank Mehra is a cybersecurity professional with 8+ years of hands-on experience in application security, penetration testing, vulnerability assessment, and AI security. He holds CEH, CAPEN, and CRTP certifications and specialises in identifying and mitigating security risks across applications and AI-powered systems.

View all posts →