Data Exposure Vulnerability in LibreOffice Calc by The Document Foundation
CVE-2026-63266

6.8MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-63266?

LibreOffice Calc has a vulnerability that allows a cell range to be linked to an external data source, which could lead to the unintended opening of an embedded Firebird database. This situation poses a risk as it enables documents to write files to any user-writable location, potentially leading to unauthorized access and data manipulation. However, in the fixed versions, the access is limited, allowing the embedded Firebird database to open or create files solely within its designated private directory.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
.