Back to News
Oct 6, 2026 • NixShield News

Malicious Spreadsheet Can Trigger Remote Code Execution in LibreOffice and OpenOffice

CVE-2026-63277 / CVE-2026-59265 - A newly disclosed vulnerability affecting LibreOffice Calc and Apache OpenOffice can allow a malicious spreadsheet to execute attacker-controlled Java code when the document is opened

linux patching vulnerability exploit security cve macro libreoffice openoffice
Malicious Spreadsheet Can Trigger Remote Code Execution in LibreOffice and OpenOffice

A newly disclosed vulnerability affecting LibreOffice Calc and Apache OpenOffice can allow a malicious spreadsheet to execute attacker-controlled Java code when the document is opened — without relying on traditional Office macros or displaying a macro security warning.

The LibreOffice vulnerability is tracked as CVE-2026-63277, while the corresponding Apache OpenOffice issue is tracked as CVE-2026-59265.

The LibreOffice vulnerability was publicly announced on October 5, 2026. Apache disclosed its OpenOffice variant on October 2 and classifies the issue as Critical.

How the Attack Works

The vulnerability abuses Calc's support for external data sources.

A spreadsheet can define a database range whose contents are retrieved from an external source. A malicious document can configure this mechanism to reference a remote database document.

That database configuration can specify a Java JDBC driver together with its Java classpath. The vulnerable implementation allowed the classpath to reference a remote JAR file.

An attack chain can therefore look like this:

Malicious spreadsheet → external data source → remote database document → JDBC configuration → remote JAR → Java code execution

When the document is opened and the external data source is processed, the office suite may retrieve the attacker-controlled Java component and instantiate the specified driver class.

Instantiating that class is sufficient for attacker-controlled Java bytecode to execute.

This makes the vulnerability particularly interesting because the attack does not depend on a traditional document macro. As a result, users may not receive the macro security warning they would normally associate with executable content.

Impact

Successful exploitation results in arbitrary code execution with the privileges of the user or service running LibreOffice/OpenOffice.

On a workstation, this could potentially allow an attacker to:

  • execute commands,
  • access files available to the logged-in user,
  • steal credentials or application data,
  • download additional malware,
  • establish persistence,
  • or pivot further into the environment.

The vulnerability may be especially relevant on Linux servers and automated document-processing systems.

LibreOffice is frequently used in headless environments for document conversion and processing. If an application automatically processes attacker-controlled spreadsheets using a vulnerable LibreOffice installation with the required Java/JDBC functionality available, exploitation may occur in the context of the service account rather than an interactive desktop user.

Affected Software

LibreOffice — CVE-2026-63277

The Document Foundation has fixed the vulnerability in:

  • LibreOffice 26.2.5
  • LibreOffice 26.8.0

Users running affected versions should upgrade to 26.2.5 / 26.8.0 or newer.

The fix changes Java classpath handling so that classpath entries supplied through this mechanism must reference local file URLs, preventing the vulnerable remote JAR loading behavior.

Apache OpenOffice — CVE-2026-59265

Apache OpenOffice versions through 4.1.16 are affected.

Apache rates the vulnerability as:

Severity: Critical

A permanent fix is expected in Apache OpenOffice 4.1.17.

Until the patched version is available, Apache recommends disabling Java runtime integration:

Tools → Options → OpenOffice → Java → disable "Use a Java runtime environment"

Organizations should also avoid opening or automatically processing untrusted documents on vulnerable installations.

Attack Requirements

The attack requires Java/JDBC functionality to be available to the office suite.

This means not every LibreOffice installation is necessarily exploitable using the described chain.

However, systems with LibreOffice Base, Java integration, JDBC drivers, or document-processing workloads deserve particular attention.

The attack surface is also not limited to files manually downloaded by users. Potential delivery paths include:

  • email attachments,
  • uploaded spreadsheets,
  • ticketing systems,
  • document management systems,
  • automated document converters,
  • web applications accepting office documents,
  • shared network folders,
  • and backend services invoking LibreOffice in headless mode.

Why This Vulnerability Matters

The most notable aspect of CVE-2026-63277 and CVE-2026-59265 is the trust boundary being crossed.

A spreadsheet is able to influence an external data-source configuration which ultimately causes Java code from a remote location to be loaded and executed.

There is no need for a conventional macro payload.

For defenders accustomed to treating macro-disabled spreadsheets as relatively safe, this represents an important distinction.

Recommended Actions

Administrators should identify systems where LibreOffice or Apache OpenOffice is installed, with particular attention to Linux servers performing automated document conversion.

For LibreOffice, upgrade to:

26.2.5, 26.8.0, or a later patched release.

For Apache OpenOffice, disable Java runtime integration until 4.1.17 is available and deployed.

Organizations should additionally review whether servers running LibreOffice require outbound Internet access. Restricting unnecessary outbound connections from document-processing services can provide an additional defensive layer against vulnerabilities that depend on retrieving attacker-controlled remote resources.

Automated document processors should ideally execute inside a restricted sandbox or container with minimal filesystem access, no unnecessary credentials, limited network connectivity, and a dedicated unprivileged service account.

Nixshield Assessment

Severity: Critical / High

Impact: Remote Code Execution

Attack Vector: Malicious document

User Interaction: Opening or processing a crafted spreadsheet

Privileges Required: None for the attacker

Primary Component: LibreOffice Calc / Apache OpenOffice Calc

Relevant Technology: Java, JDBC, external data sources

Internet Exposure Required: No — the malicious document can be delivered through other channels

Outbound Network Access: Relevant to remote payload retrieval

Patch Available: Yes for LibreOffice; OpenOffice 4.1.17 pending at disclosure

Linux Relevance: High

Server Relevance: High where untrusted documents are processed automatically

Nixshield Priority

Patch promptly on workstations.

Treat as high priority on servers that automatically process user-supplied Office documents.

Document-processing servers should additionally be checked for Java integration and unnecessary outbound network access.

Need help with Linux patching and vulnerability remediation?

Talk with us about on-premise deployment and practical workflows for faster patch response.