Decoding the world of cybersecurity

·

LibreOffice and OpenOffice flaws allow code execution through crafted documents

LibreOffice has fixed a Calc vulnerability that can load remote Java code, while Apache OpenOffice has disclosed a related critical flaw affecting versions through 4.1.16.

LibreOffice and OpenOffice flaws allow code execution through crafted documents
Summary
  • LibreOffice CVE-2026-63277 can load a remote Java database driver when a crafted Calc document is opened.
  • LibreOffice fixed the vulnerability in versions 26.2.5 and 26.8.0.
  • Apache OpenOffice says a related flaw affects versions through 4.1.16 and can allow arbitrary code execution.

Security flaws in LibreOffice and Apache OpenOffice can allow malicious office documents to trigger attacker-controlled code when opened by a user.

LibreOffice disclosed CVE-2026-63277 on 5 October. The vulnerability sits within Calc functionality that allows a cell range to connect to an external data source, with details of that connection stored inside the document.

A specially prepared file could specify a Java database driver hosted remotely. Vulnerable versions of LibreOffice could load that driver when the document was opened, allowing Java code from the remote location to execute.

The Document Foundation has corrected the behaviour in LibreOffice 26.2.5 and 26.8.0. In the fixed versions, the relevant Java class path has to use a local file URL rather than a remote location.

Apache OpenOffice has separately disclosed CVE-2026-59265, which it rates as critical. Apache says a malicious document can use the related weakness to cause arbitrary code to run when the file is opened.

Office documents become the delivery mechanism

The vulnerability does not depend on an attacker disguising a conventional executable as a spreadsheet. Malicious content inside the document influences legitimate application functionality that can load code, moving the execution route into the office suite itself.

That mechanism gives the flaw a natural delivery channel. Office documents routinely reach organisations through email, shared storage, collaboration platforms and customer workflows. A weakness activated during document processing can therefore travel through ordinary business processes even where executable attachments are restricted.

LibreOffice users can move immediately to a corrected release. The project recommends version 26.2.5, 26.8.0 or later.

Apache says OpenOffice versions up to and including 4.1.16 are affected. Version 4.1.17 is intended to contain the correction but had not reached its final release when the advisory was published.

Until that update is available, Apache recommends disabling Java runtime integration. It also advises against opening untrusted documents where the mitigation cannot be applied or where additional caution is required.

The projects use different CVE identifiers even though the technical issues are related. Apache’s advisory explicitly refers to the LibreOffice disclosure, and researchers involved in identifying the weaknesses are credited across both projects.

Neither project says the vulnerabilities are being exploited in the wild. Public disclosure gives defenders information they can use to patch or mitigate the issue, while also making technical details more widely available, but it does not establish that any organisation has already been compromised.

The exposure also differs according to version and configuration. Updated LibreOffice installations no longer contain the vulnerable behaviour described under CVE-2026-63277. OpenOffice remains affected through version 4.1.16, with Java disabling serving as the principal interim mitigation described by Apache.

The vulnerabilities illustrate how file formats and application features can become part of an execution path. A document is normally treated as data for an office application to process, but the affected Java functionality allowed malicious document content to influence what code the application loaded.

LibreOffice users have a completed upgrade route, while OpenOffice users may need to rely on the interim mitigation until version 4.1.17 reaches final release.

×