Data Exposure Vulnerability in LibreOffice Calc by The Document Foundation
CVE-2026-63266
6.8MEDIUM
What is CVE-2026-63266?
LibreOffice Calc has a vulnerability that allows a cell range to be linked to an external data source, which could lead to the unintended opening of an embedded Firebird database. This situation poses a risk as it enables documents to write files to any user-writable location, potentially leading to unauthorized access and data manipulation. However, in the fixed versions, the access is limited, allowing the embedded Firebird database to open or create files solely within its designated private directory.
Affected Version(s)
LibreOffice 26.2
References
CVSS V4
Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
