LibreOffice fixes spreadsheet flaw that runs code with no macro warning; OpenOffice waits
LibreOffice 26.2.5 and 26.8.0 close a flaw that lets a crafted spreadsheet load a remote Java database driver and execute code silently. Apache OpenOffice has no fix yet.
At a glance
- LibreOffice patched CVE-2026-63277 on October 5 in versions 26.2.5 and 26.8.0; Apache OpenOffice is tracked as CVE-2026-59265 and remains unfixed through 4.1.16
- The chain abuses auto-refreshing external database ranges in spreadsheets, so no macro security prompt is shown
- A proof of concept is public, but according to The Hacker News there are no reports of exploitation in the wild
- OpenOffice users are advised to disable Java support or avoid untrusted spreadsheets until 4.1.17 ships
LibreOffice released security updates on October 5, 2026 for a vulnerability that lets a specially crafted spreadsheet execute code on a victim's computer without ever showing the macro security warning that office users are trained to look for. The LibreOffice project tracks the issue as CVE-2026-63277 and says it is fixed in versions 26.2.5 and 26.8.0. According to The Hacker News, the same weakness affects Apache OpenOffice as CVE-2026-59265, where every release up to and including 4.1.16 is vulnerable and a fix is only expected in 4.1.17.
What happened
The Document Foundation's advisory page describes CVE-2026-63277 as remote code execution "via calcext:data-mappings, sql provider and jdbc connector", and says malicious documents could be used to load Java database drivers from remote locations. The same advisory batch, published on October 5, lists two further issues fixed in the same releases: CVE-2026-63270, described as environment and ini-file leaks that can expose sensitive environment data through crafted URLs, and CVE-2026-63269, a local file inclusion and GET-based server-side request forgery issue involving GStreamer and HLS playlists during document loading.
The Hacker News reports that the flaws were found by Rick de Jager of V12 Security together with Thomas Rinsma and Edoardo Geraci of Codean Labs, and that a proof of concept has been published. The same report says no exploitation in the wild has been observed so far. Neither source reviewed for this article published a CVSS score for the spreadsheet flaw.
Technical details
What makes the issue notable is that it chains features that are working as designed rather than relying on a memory corruption bug. As The Hacker News explains it, a spreadsheet can define external database ranges that refresh automatically from a URL. When Java support is enabled in the office suite, that refresh can be pointed at a malicious ODB database file that brings its own Java JDBC driver with it, and loading the driver results in code execution. Because none of the steps involve a document macro, the macro security dialog that normally stands between an untrusted file and code execution never appears.
Who is affected
Any LibreOffice installation older than 26.2.5 or 26.8.0 and any Apache OpenOffice installation up to 4.1.16 is in scope. Exposure is highest where Java support is enabled and where spreadsheets routinely arrive by email or download, which covers a large share of public sector and enterprise desktops. Linux users should note that distribution packages often trail upstream releases, so the version in a repository may still be vulnerable after the upstream fix.
What to do
Update LibreOffice to 26.2.5 or 26.8.0 as soon as the packaged build is available. For Apache OpenOffice, where no patched release exists yet, the mitigation advice reported by The Hacker News is to disable Java support in the application's settings or to avoid opening spreadsheets from untrusted sources until 4.1.17 is released; disabling Java breaks the driver-loading step the chain depends on. On the detection side, office suite processes reaching out to the internet to fetch a database file, or spawning a Java process, are both unusual enough to be worth alerting on.
Related CVEs
Sources
- LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings — The Hacker News
- LibreOffice Security Advisories — The Document Foundation
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



