Skip to content
TrustList
News

LibreOffice fixes Calc code-execution flaw; OpenOffice 4.1.16 still open

Editorial

By TrustList Editorial

A crafted spreadsheet can load remote Java code with no macro prompt when Java support is on. A proof of concept is public, and the Apache fix is still in release candidate.

About LibreOffice fixes Calc code-execution flaw; OpenOffice 4.1.16 still open

LibreOffice fixes Calc code-execution flaw; OpenOffice 4.1.16 still open

5 October 2026: LibreOffice has patched CVE-2026-63277, a flaw that lets a crafted Calc spreadsheet load a Java database driver from a remote location and run its code as soon as the file is opened. Fixed versions are LibreOffice 26.2.5 and 26.8.0. Apache OpenOffice, which has the matching flaw as CVE-2026-59265, has no fix yet: every version up to and including 4.1.16 is affected.

Not yet independently verified. Neither advisory gives a severity score, and exploitation status comes from press reporting only. The Apache OpenOffice release date for 4.1.17 is not stated. We will update this when it can be confirmed, and remove this note.

The LibreOffice advisory, announced on 5 October, explains the route. Calc can link a cell range to an external data source and save that link in the document. A document could name a Java database driver for such a link, to be loaded from a remote location, so opening it could run Java code from there. In the fixed versions an entry in a Java class path has to be a file URL.

The Hacker News reports that the attack works only when Java support is enabled, that no warning appears of the kind users see before a macro runs, and that a proof of concept from the V12 security team is public. It found no reports of attacks in the wild. The flaw was reported independently by Rick de Jager of V12 and by Thomas Rinsma and Edoardo Geraci of Codean Labs, and Caolan McNamara of Collabora Productivity wrote the LibreOffice fix.

Apache's advisory says the OpenOffice fix is expected in 4.1.17, which is in the release candidate phase, and that OpenOffice.org versions may also be affected. Until then it tells users to switch off the Java runtime in the program settings (Tools, Options, OpenOffice, Java, then untick the option to use a Java runtime environment), or to avoid opening untrusted files at all.

LibreOffice's advisory page lists other Calc flaws announced the same day, among them data links that could read a local file into a sheet when a document loads. Anyone running 26.2.x or earlier should move to 26.2.5 rather than apply only the Java setting change.

Company profile on TrustList: The Document Foundation

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy