LibreOffice patches critical Java-based spreadsheet flaw
LibreOffice and Apache OpenOffice contain a critical vulnerability allowing malicious spreadsheets to execute arbitrary Java code without macro warnings.

A critical vulnerability in LibreOffice and Apache OpenOffice allows a malicious spreadsheet to execute attacker-controlled Java code automatically when opened, bypassing all macro security warnings. The flaw, tracked as CVE-2026-63277 in LibreOffice and CVE-2026-59265 in Apache OpenOffice, was independently discovered by researchers Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. Both teams confirmed the same attack vector works against the two popular open-source office suites.
How the attack works
The exploit chain leverages the 'database range' feature in the Calc spreadsheet component. This feature can be configured to auto-refresh data from an external source. An attacker can embed a web address pointing to a malicious ODB database file within a spreadsheet.
When the file opens, the program downloads this ODB file. That file, in turn, can specify a JDBC driver whose code is stored in a remote JAR file. LibreOffice or OpenOffice then fetches and executes the Java code from that JAR file without prompting the user for consent. Each step in this process functions as designed, but their combination leads to silent code execution. The attack bypasses the standard security dialog that asks a user to trust a document before running macros.
Rick de Jager said: "The attack works only when the program's Java support is enabled." The vulnerability was successfully demonstrated on both Windows and Linux systems, proving it is not operating system dependent.
Impact and mitigation
The vulnerability affects all versions of LibreOffice prior to the patched releases and every version of Apache OpenOffice up to and including 4.1.16. The primary mitigation is to apply vendor-issued patches for CVE.
| Software | Affected Versions | Patched Versions | CVE Identifier |
|---|---|---|---|
| LibreOffice | All versions before 26.2.5 and 26.8.0 | 26.2.5, 26.8.0 (released Oct 5) | CVE-2026-63277 |
| Apache OpenOffice | All versions up to and including 4.1.16 | Fix expected in 4.1.17 (in testing) | CVE-2026-59265 |
LibreOffice has already fixed the flaw. Caolán McNamara of Collabora Productivity developed the fix, which restricts Java classpath entries to local file URLs only. For systems that cannot be updated immediately, disabling Java support in the office suite's settings breaks the attack chain. Users are also advised to exercise caution with spreadsheets from untrusted sources.
Additional fixes and context
The latest LibreOffice updates resolve several related vulnerabilities in Calc's external data handling. These additional fixes close security gaps that could have led to arbitrary file reads or writes.
The builds address CVE-2026-63266, which allowed arbitrary file writes through Calc data mappings and SQL provider functions. They also fix CVE-2026-63267, which let a linked CSV source read a local file into a sheet on load. All three CVEs stem from Calc reaching out to external data sources during document loading, before the user has granted any permission. The patch ensures these external data links are now handled "under the same link update control as other links."
Current status and proof of concept
To date, the vulnerability has only been demonstrated in a controlled environment with no confirmed real-world exploitation. In the proof-of-concept demonstration published by V12, the malicious Java code launched the system's Calculator application as a harmless stand-in for a real payload. A live attack would host the malicious ODB and JAR files on an attacker-controlled server.
Apache OpenOffice expects a fix in version 4.1.17, which is currently undergoing testing. No severity score has been publicly assigned to either CVE yet. Users should upgrade LibreOffice to version 26.2.5 or 26.8.0 or disable Java support as an interim measure.





