A newly disclosed vulnerability affecting LibreOffice Calc and Apache OpenOffice can allow a malicious spreadsheet to execute attacker-controlled Java code when the document is opened — without relying on traditional Office macros or displaying a macro security warning.
The LibreOffice vulnerability is tracked as CVE-2026-63277, while the corresponding Apache OpenOffice issue is tracked as CVE-2026-59265.
The LibreOffice vulnerability was publicly announced on October 5, 2026. Apache disclosed its OpenOffice variant on October 2 and classifies the issue as Critical.
How the Attack Works
The vulnerability abuses Calc's support for external data sources.
A spreadsheet can define a database range whose contents are retrieved from an external source. A malicious document can configure this mechanism to reference a remote database document.
That database configuration can specify a Java JDBC driver together with its Java classpath. The vulnerable implementation allowed the classpath to reference a remote JAR file.
An attack chain can therefore look like this:
Malicious spreadsheet → external data source → remote database document → JDBC configuration → remote JAR → Java code execution
When the document is opened and the external data source is processed, the office suite may retrieve the attacker-controlled Java component and instantiate the specified driver class.
Instantiating that class is sufficient for attacker-controlled Java bytecode to execute.
This makes the vulnerability particularly interesting because the attack does not depend on a traditional document macro. As a result, users may not receive the macro security warning they would normally associate with executable content.
Impact
Successful exploitation results in arbitrary code execution with the privileges of the user or service running LibreOffice/OpenOffice.
On a workstation, this could potentially allow an attacker to:
- execute commands,
- access files available to the logged-in user,
- steal credentials or application data,
- download additional malware,
- establish persistence,
- or pivot further into the environment.
The vulnerability may be especially relevant on Linux servers and automated document-processing systems.
LibreOffice is frequently used in headless environments for document conversion and processing. If an application automatically processes attacker-controlled spreadsheets using a vulnerable LibreOffice installation with the required Java/JDBC functionality available, exploitation may occur in the context of the service account rather than an interactive desktop user.
Affected Software
LibreOffice — CVE-2026-63277
The Document Foundation has fixed the vulnerability in:
- LibreOffice 26.2.5
- LibreOffice 26.8.0
Users running affected versions should upgrade to 26.2.5 / 26.8.0 or newer.
The fix changes Java classpath handling so that classpath entries supplied through this mechanism must reference local file URLs, preventing the vulnerable remote JAR loading behavior.
Apache OpenOffice — CVE-2026-59265
Apache OpenOffice versions through 4.1.16 are affected.
Apache rates the vulnerability as:
Severity: Critical
A permanent fix is expected in Apache OpenOffice 4.1.17.
Until the patched version is available, Apache recommends disabling Java runtime integration:
Tools → Options → OpenOffice → Java → disable "Use a Java runtime environment"
Organizations should also avoid opening or automatically processing untrusted documents on vulnerable installations.
Attack Requirements
The attack requires Java/JDBC functionality to be available to the office suite.
This means not every LibreOffice installation is necessarily exploitable using the described chain.
However, systems with LibreOffice Base, Java integration, JDBC drivers, or document-processing workloads deserve particular attention.
The attack surface is also not limited to files manually downloaded by users. Potential delivery paths include:
- email attachments,
- uploaded spreadsheets,
- ticketing systems,
- document management systems,
- automated document converters,
- web applications accepting office documents,
- shared network folders,
- and backend services invoking LibreOffice in headless mode.
Why This Vulnerability Matters
The most notable aspect of CVE-2026-63277 and CVE-2026-59265 is the trust boundary being crossed.
A spreadsheet is able to influence an external data-source configuration which ultimately causes Java code from a remote location to be loaded and executed.
There is no need for a conventional macro payload.
For defenders accustomed to treating macro-disabled spreadsheets as relatively safe, this represents an important distinction.
Recommended Actions
Administrators should identify systems where LibreOffice or Apache OpenOffice is installed, with particular attention to Linux servers performing automated document conversion.
For LibreOffice, upgrade to:
26.2.5, 26.8.0, or a later patched release.
For Apache OpenOffice, disable Java runtime integration until 4.1.17 is available and deployed.
Organizations should additionally review whether servers running LibreOffice require outbound Internet access. Restricting unnecessary outbound connections from document-processing services can provide an additional defensive layer against vulnerabilities that depend on retrieving attacker-controlled remote resources.
Automated document processors should ideally execute inside a restricted sandbox or container with minimal filesystem access, no unnecessary credentials, limited network connectivity, and a dedicated unprivileged service account.
Nixshield Assessment
Severity: Critical / High
Impact: Remote Code Execution
Attack Vector: Malicious document
User Interaction: Opening or processing a crafted spreadsheet
Privileges Required: None for the attacker
Primary Component: LibreOffice Calc / Apache OpenOffice Calc
Relevant Technology: Java, JDBC, external data sources
Internet Exposure Required: No — the malicious document can be delivered through other channels
Outbound Network Access: Relevant to remote payload retrieval
Patch Available: Yes for LibreOffice; OpenOffice 4.1.17 pending at disclosure
Linux Relevance: High
Server Relevance: High where untrusted documents are processed automatically
Nixshield Priority
Patch promptly on workstations.
Treat as high priority on servers that automatically process user-supplied Office documents.
Document-processing servers should additionally be checked for Java integration and unnecessary outbound network access.