AI description
CVE-2026-63277 is a vulnerability in LibreOffice Calc that allows a spreadsheet to execute arbitrary Java code when opened. The issue stems from a feature called "database range," which allows a block of cells to pull and refresh data from an external source. A crafted spreadsheet can point to a remote database document (an ODB file) that specifies a Java database driver (JDBC driver) hosted on an external server. When the spreadsheet is opened, Calc automatically downloads and runs the remote Java code without displaying the typical warnings associated with macros. The vulnerability only affects systems where Java support is enabled within the office suite. LibreOffice addressed the flaw in its October 5, 2026 updates (versions 26.2.5 and 26.8.0) by requiring that entries in a Java class path use a local file URL. A matching vulnerability exists in Apache OpenOffice (tracked as CVE-2026-59265), which remains unpatched in versions up to 4.1.16, though users can mitigate the risk by disabling Java support in their settings.
- Description
- LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
- Source
- security@documentfoundation.org
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 8.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- security@documentfoundation.org
- CWE-829
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
7
⚠️ MALICIOUS SPREADSHEETS CAN RUN CODE IN LIBREOFFICE AND APACHE OPENOFFICE Both open-source office suites have published advisories for document flaws that trigger as soon as a crafted file is opened. LibreOffice (announced Oct 5): * CVE-2026-63277: a Calc spreadsheet's h
@DailyDarkWeb
6 Oct 2026
3592 Impressions
0 Retweets
4 Likes
2 Bookmarks
0 Replies
2 Quotes
Two office suites, one Java risk. CVE-2026-63277 (LibreOffice): fixed in 26.2.5 and 26.8.0. CVE-2026-59265 (Apache OpenOffice): no fix yet, 4.1.17 is in release candidate. VulnTracker recommends updating LibreOffice and disabling Java in OpenOffice until the patch lands. https://
@vuln_tracker
6 Oct 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes