Vulnerabilities
LibreOffice and OpenOffice spreadsheets that run Java code
CVE-2026-63277 and CVE-2026-59265 let a Calc spreadsheet load a remote Java driver with no macro prompt. Fixed versions, the Java toggle and checks.
A crafted Calc spreadsheet can make LibreOffice or Apache OpenOffice download a Java database driver from an attacker's server and run it the moment the file is opened. No macro warning or active content prompt appears first. LibreOffice tracks the flaw as CVE-2026-63277, rated 8.5 on CVSS 4.0, and announced it on October 5. Apache OpenOffice tracks the same bug as CVE-2026-59265, rates it critical, and published its advisory on October 2.
The attack needs Java support to be installed and switched on in the office suite. The two projects are at different stages: LibreOffice 26.2.5 and 26.8.0 already contain the fix, while every OpenOffice release up to and including 4.1.16 is vulnerable and the fix waits on 4.1.17, still a release candidate. A working proof of concept is public on GitHub. No use in real attacks has been reported.
How it works
Calc can link a block of cells to an outside data source and refresh it on a timer. This is a database range, and it is saved inside the .ods file as a table:database-range element. Rick de Jager of the V12 security team, who found the bug independently of Thomas Rinsma and Edoardo Geraci of Codean Labs, built a proof of concept whose range refreshes every second (table:refresh-delay="PT1S") and whose data source is a web address: table:database-name="http://.../poc-calculator.odb".
An ODB is an OpenDocument database file, the format LibreOffice Base uses. It can hold JDBC settings, the connection details for a Java database driver. The attacker's ODB sets two of them: db:java-driver-class, the name of the driver class, and db:java-classpath, where to load that class from. In the proof of concept the classpath is jar:http://.../evil-calculator-driver.jar!/, a JAR file on the attacker's server.
When Calc opens the spreadsheet it restores the range and starts the refresh. The refresh creates a row set, the row set resolves the URL through the suite's database context, the database context downloads and loads the ODB, and the Java classpath code accepts the jar:http entry. The suite then fetches the JAR and instantiates the named driver class. Creating the class runs its code inside the office process, with the user's rights. The demonstration driver starts Calculator.
Each step is a supported feature. The researchers' point is that chaining them carries a document from passive data into code execution without the trust decision the suite enforces for macros. De Jager confirmed it on LibreOffice 24.2.7 on Ubuntu 24.04, LibreOffice 26.2.4 on Windows and OpenOffice 4.1.16 on Linux Mint 22.3, and expects it to work on any platform.
LibreOffice's fix is narrow and clear: in patched builds an entry in a Java classpath must be a file: URL, so a document can no longer pull a driver from the network.
Five related LibreOffice fixes
Codean Labs reported more ways to abuse the same external data links, saved in the document as calcext:data-mappings. LibreOffice fixed them in the same releases, all announced on October 5:
- CVE-2026-63266: a link could open an embedded Firebird database that wrote a file anywhere the user can write.
- CVE-2026-63267: a csv link was fetched while the document loaded, so it could read a local file into the sheet or send a request to any host.
- CVE-2026-63268: an sql link could treat a folder of local text files as a database and read one into the sheet.
- CVE-2026-63269: on Linux, a linked media file could be an HLS playlist that made GStreamer read local files and remote URLs.
- CVE-2026-63270: document URLs could expand environment variables or INI file values and send them to a remote server, a gap the CVE-2024-12426 fix left open.
Fixed builds now restore only the csv, html and xml data providers when a document loads, and put external data links and linked media under the same link update control as other links.
What attackers are doing
No exploitation has been reported for either CVE. The proof of concept, in the v12-security/pocs repository on GitHub, includes a script that builds the spreadsheet, ODB and JAR for any host, so turning it into a phishing attachment takes little work. Our expectation, not a reported fact, is that it will show up in malicious mail aimed at Linux desktops and at organisations that standardised on LibreOffice or OpenOffice.
What to do
1. Update LibreOffice
Move every install to 26.2.5 or later, or to 26.8.0 or later. Both shipped weeks before the advisory: 26.2.5 in late July and 26.8.0 on August 26. Check Help > About. Linux distributions often ship older branches with backported fixes, such as the 24.2.7 package on Ubuntu 24.04 that the researcher tested, so check your distribution's tracker for CVE-2026-63277 rather than comparing version numbers. Include servers that run soffice --headless to convert or preview uploaded files.
2. OpenOffice: turn Java off now
There is no OpenOffice fix yet. The project's advice is to open Tools > Options > OpenOffice > Java (OpenOffice > Preferences > OpenOffice > Java on macOS) and untick "Use a Java runtime environment". That stops the attack. LibreOffice's advisory lists no workaround, but the same switch exists under Tools > Options > LibreOffice > Advanced, and since the attack depends on Java, turning it off on any unpatched install removes the route. Java is needed for some Base databases and a few extensions, so check with their users first.
Longer term, plan a move off OpenOffice: this critical bug has a public proof of concept and its fix is still in release candidate testing.
3. Check whether you were hit
- Look inside suspicious spreadsheets. An
.odsis a ZIP archive:unzip -p file.ods content.xml | grep -o 'table:database-name="http[^"]*"'prints any database range that points at a web address. Flat.fodsfiles can be searched directly. - Search web proxy logs for requests that fetch
.odbor.jarfiles, especially from workstations wheresoffice.binwas running at the time. Opening an ordinary spreadsheet does not fetch either. - In your EDR, hunt for child processes of
soffice.bin, the office process on both Linux and Windows, such as shells, PowerShell,curlorwget. Since the driver runs inside the office process, also review outbound connections from that process. - Check mail gateway logs for
.odsand.fodsattachments from outside senders since the start of October.
4. If you find a hit
Treat the workstation as compromised: isolate it, collect the spreadsheet and any downloaded JAR, and rebuild it. The code ran as the user, so reset that user's passwords and revoke their sessions and tokens, along with any credentials stored in browsers or files they could read.
The wider lesson
Macro warnings teach people that a document without macros is safe to open. This bug and the five fixed with it show other paths from a document to the network and to code: linked data, database drivers, media playlists. Know where office suites and Java runtimes are installed, servers included, and keep document converters in patch scope.
Our safeguarding and hardening work covers office suite settings such as the Java runtime switch across a fleet, and security operations can turn the hunting queries above into standing detections. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: LibreOffice security advisories, Apache OpenOffice CVE-2026-59265 advisory, oss-security announcement, V12 security proof of concept and report, The Hacker News, heise online, Cyber Kendra, LibreOffice help: Advanced options, Phoronix on LibreOffice 26.8.