Out-of-Bounds Write Vulnerability in LibreOffice by The Document Foundation
CVE-2026-4430

5.4MEDIUM

Key Information:

Vendor
CVE Published:
7 May 2026

What is CVE-2026-4430?

An out-of-bounds write vulnerability exists in The Document Foundation's LibreOffice, which could be triggered by processing specially crafted OOXML documents that contain mismatched encryption salt parameters. This flaw potentially allows attackers to overwrite memory and execute arbitrary code, jeopardizing user data and system stability.

Affected Version(s)

LibreOffice 26.2 < 26.2.3

LibreOffice 25.8 < 25.8.7

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Duc Anh Nguyen (@Danzation)
Caolán McNamara <caolan.mcnamara@collabora.com>
.