Remote Code Execution Risk in LibreOffice Calc by LibreOffice
CVE-2026-63277

8.5HIGH

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-63277?

LibreOffice Calc allows users to link cell ranges to external data sources. This feature poses a risk, as documents can specify a Java database driver that points to a remote location. Consequently, when users open the document, Java code from that external source can be executed on their system, leading to potential unauthorized actions. To mitigate this issue, fixed versions of LibreOffice enforce that entries in the Java class path must be file URLs, preventing the loading of remote Java code.

Affected Version(s)

LibreOffice 26.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rick de Jager of the V12 security team
Thomas Rinsma and Edoardo Geraci from Codean Labs
Caolán McNamara of Collabora Productivity
.