Exposed Environment Variables in LibreOffice Document Links
CVE-2026-63278
6.7MEDIUM
What is CVE-2026-63278?
An issue exists in LibreOffice where specially crafted URLs could manipulate environment variables or INI file values, leading to the potential exposure of sensitive information. By opening a document containing such links, attackers may exfiltrate data to a remote server. This vulnerability arose due to insufficient checks in the previous security patch, allowing alternate naming of the package content provider. In fixed versions, enhanced checks ensure that the package content provider matches correctly, thus preventing unauthorized data access.
Affected Version(s)
LibreOffice 26.2
References
CVSS V4
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Darren Xuan of Tanto Security
Caolán McNamara of Collabora Productivity
