Data Leakage Vulnerability in LibreOffice Calc
CVE-2026-63267

6.7MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-63267?

LibreOffice Calc allows users to link cell ranges to external CSV data sources, which are saved within the document. This functionality can lead to potential data leakage as opening a document may unknowingly fetch local files or send requests to external hosts defined within the document. Users are encouraged to update to the latest versions where these external data links are managed securely to mitigate this risk.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
.