Code Execution Flaw in Java Integration of Apache OpenOffice by Apache
CVE-2026-59265

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
2 October 2026

What is CVE-2026-59265?

A vulnerability in the Java integration of Apache OpenOffice versions 4.1.16 and earlier allows attackers to execute arbitrary code through carefully crafted untrusted documents. This can lead to unauthorized actions being performed on the user's system upon opening the compromised document. To mitigate this risk, users are advised to disable the Java runtime integration via the Preferences dialog or refrain from opening untrusted files. The issue is scheduled to be resolved in version 4.1.17, currently in the release candidate phase.

Affected Version(s)

Apache OpenOffice 0 <= 4.1.16

Apache OpenOffice 0 < 95923fd437e06edd38a4f0e139a27c755a6f3ba6

Apache OpenOffice 0 < 181421139242694b309751fb666406eddc203c50

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Rinsma and Edoardo Geraci from Codean Labs
Rick de Jager
.