Remote Code Execution Risk in LibreOffice Calc by LibreOffice
CVE-2026-63277
8.5HIGH
What is CVE-2026-63277?
LibreOffice Calc allows users to link cell ranges to external data sources. This feature poses a risk, as documents can specify a Java database driver that points to a remote location. Consequently, when users open the document, Java code from that external source can be executed on their system, leading to potential unauthorized actions. To mitigate this issue, fixed versions of LibreOffice enforce that entries in the Java class path must be file URLs, preventing the loading of remote Java code.
Affected Version(s)
LibreOffice 26.2
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rick de Jager of the V12 security team
Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
