CVE-2026-63277

Published Oct 5, 2026

Last updated 2 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-63277 is a vulnerability in LibreOffice Calc that allows a spreadsheet to execute arbitrary Java code when opened. The issue stems from a feature called "database range," which allows a block of cells to pull and refresh data from an external source. A crafted spreadsheet can point to a remote database document (an ODB file) that specifies a Java database driver (JDBC driver) hosted on an external server. When the spreadsheet is opened, Calc automatically downloads and runs the remote Java code without displaying the typical warnings associated with macros. The vulnerability only affects systems where Java support is enabled within the office suite. LibreOffice addressed the flaw in its October 5, 2026 updates (versions 26.2.5 and 26.8.0) by requiring that entries in a Java class path use a local file URL. A matching vulnerability exists in Apache OpenOffice (tracked as CVE-2026-59265), which remains unpatched in versions up to 4.1.16, though users can mitigate the risk by disabling Java support in their settings.

Description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
Source
security@documentfoundation.org
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.5
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

Weaknesses

security@documentfoundation.org
CWE-829

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

7

References

Sources include official advisories and independent security research.