Skip to content

Image: thaicert.or.th · rights & removal

Executive Summary

Vulnerabilities have been disclosed affecting LibreOffice Calc and Apache OpenOffice Calc, tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice. These flaws allow attackers to execute Java code on a user's device by exploiting how the software links data. An attacker can craft a spreadsheet file that connects to an external ODB database and sets the configuration to use a JDBC driver loaded from a JAR file hosted on an attacker-controlled server. When a victim opens the malicious document with Java Support enabled, the application may download the external file, enabling the execution of attacker-controlled Java code. The software does not display warnings before this code executes. Patches are available for LibreOffice in versions 26.2.5 and 26.8.0, and for Apache OpenOffice, version 4.1.17 includes the fix, though it is currently in Release Candidate status. Users are advised to update or disable Java Runtime Integration until patching is complete.

Facts Only

* Vulnerabilities affect LibreOffice Calc (CVE-2026-63277) and Apache OpenOffice Calc (CVE-2026-59265).
* Exploitation requires opening a malicious file with Java Support enabled.
* The attack involves linking data to an external ODB database file hosted externally.
* The database configuration can load a JDBC driver from a JAR file on an attacker-controlled server.
* Opening the document may cause the application to connect to the external source and download the JAR file, executing attacker Java code.
* LibreOffice has addressed CVE-2026-63277 in versions 26.2.5 and 26.8.0.
* Apache OpenOffice versions 4.1.16 and earlier are affected by CVE-2026-59265; version 4.1.17 is a Release Candidate.
* Proof-of-Concept exploits have been released.
* Testing was successful on both Windows and Linux systems.

Full Take

The mechanism described reveals a critical vulnerability chain where the feature intended for external data linking (connecting spreadsheets to external sources) is leveraged to bypass standard security controls by introducing arbitrary code execution capabilities via Java components. The core implication is that a seemingly benign feature can become an indirect vector for remote code execution, shifting the risk profile from file manipulation to system compromise. The fact that the vulnerability relies on specific application settings being active (Java Support enabled) highlights a failure in the default security posture of these applications, suggesting that reliance on user configuration rather than inherent design security is a significant systemic weakness.
The pattern observed is one where advanced functionality introduces exploitable pathways that remain hidden from typical surface-level scanning or warnings, exemplified by the gap between feature exposure and security notification. The narrative frames remediation around patching specific versions, which creates an immediate pressure for updates. However, the deeper question arises about the long-term implications: if file formats can inherently facilitate remote code execution through complex data linkage, what does this imply about the security assumptions built into document processing workflows? Who bears the cost of mitigating these risk surfaces—the end-user forced to manage Java integration, or the vendors responsible for designing features that possess such latent attack surface?
BRIDGE QUESTIONS: If applications are designed to facilitate external data linkage, how should the security architecture shift from patching individual vulnerabilities to fundamentally restricting what external components an application is permitted to load during runtime? What systemic changes are required to ensure that feature exposure does not automatically translate into unmanaged remote code execution risk? What mechanisms can developers implement to enforce principle of least privilege across linked data sources without breaking essential functionality?

From the original · Thailand ThaiCERT Advisories

552/69 Wednesday, October 7, 2026 Security researchers have disclosed vulnerabilities affecting LibreOffice Calc and Apache OpenOffice Calc that could allow attackers to execute Java code on a user’s device through a specially crafted spreadsheet file. The vulnerabilities are tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice.
Read the full story at thaicert.or.th

Sentinel — Human

Confidence

The text reads like a factual summary derived directly from security research, characterized by precise technical detail and clear attribution to specific vulnerabilities and fixes.

Signals Detected
low severity: Moderate sentence length variance; factual, technical tone.
low severity: High coherence; clear flow from vulnerability disclosure to technical mechanism to remediation.
low severity: Direct reporting of CVEs, versions, and specific software entities suggests direct sourcing.
low severity: The information presents very specific technical details (CVEs, version numbers) that align with real-world security reporting patterns.
Human Indicators
Citations of specific CVE numbers and software versions; direct inclusion of vendor recommendations; the structure reflects typical security advisory reporting.
Vulnerabilities Found in LibreOffice Calc and Apache OpenOffice Calc Could Allow Code Execution on Users’ Devices | Huntaegis