Image: thaicert.or.th · rights & removal
Vulnerabilities Found in LibreOffice Calc and Apache OpenOffice Calc Could Allow Code Execution on Users’ Devices
Reporting by Thailand ThaiCERT AdvisoriesRead the original at thaicert.or.th
Executive Summary
Facts Only
* Vulnerabilities affect LibreOffice Calc (CVE-2026-63277) and Apache OpenOffice Calc (CVE-2026-59265).
* Exploitation requires opening a malicious file with Java Support enabled.
* The attack involves linking data to an external ODB database file hosted externally.
* The database configuration can load a JDBC driver from a JAR file on an attacker-controlled server.
* Opening the document may cause the application to connect to the external source and download the JAR file, executing attacker Java code.
* LibreOffice has addressed CVE-2026-63277 in versions 26.2.5 and 26.8.0.
* Apache OpenOffice versions 4.1.16 and earlier are affected by CVE-2026-59265; version 4.1.17 is a Release Candidate.
* Proof-of-Concept exploits have been released.
* Testing was successful on both Windows and Linux systems.
Full Take
The mechanism described reveals a critical vulnerability chain where the feature intended for external data linking (connecting spreadsheets to external sources) is leveraged to bypass standard security controls by introducing arbitrary code execution capabilities via Java components. The core implication is that a seemingly benign feature can become an indirect vector for remote code execution, shifting the risk profile from file manipulation to system compromise. The fact that the vulnerability relies on specific application settings being active (Java Support enabled) highlights a failure in the default security posture of these applications, suggesting that reliance on user configuration rather than inherent design security is a significant systemic weakness.
The pattern observed is one where advanced functionality introduces exploitable pathways that remain hidden from typical surface-level scanning or warnings, exemplified by the gap between feature exposure and security notification. The narrative frames remediation around patching specific versions, which creates an immediate pressure for updates. However, the deeper question arises about the long-term implications: if file formats can inherently facilitate remote code execution through complex data linkage, what does this imply about the security assumptions built into document processing workflows? Who bears the cost of mitigating these risk surfaces—the end-user forced to manage Java integration, or the vendors responsible for designing features that possess such latent attack surface?
BRIDGE QUESTIONS: If applications are designed to facilitate external data linkage, how should the security architecture shift from patching individual vulnerabilities to fundamentally restricting what external components an application is permitted to load during runtime? What systemic changes are required to ensure that feature exposure does not automatically translate into unmanaged remote code execution risk? What mechanisms can developers implement to enforce principle of least privilege across linked data sources without breaking essential functionality?
From the original · Thailand ThaiCERT Advisories
552/69 Wednesday, October 7, 2026 Security researchers have disclosed vulnerabilities affecting LibreOffice Calc and Apache OpenOffice Calc that could allow attackers to execute Java code on a user’s device through a specially crafted spreadsheet file. The vulnerabilities are tracked as CVE-2026-63277 for LibreOffice and CVE-2026-59265 for Apache OpenOffice.Read the full story at thaicert.or.th
Sentinel — Human
The text reads like a factual summary derived directly from security research, characterized by precise technical detail and clear attribution to specific vulnerabilities and fixes.
