LibreOffice Patches Spreadsheet Code Execution Flaw; OpenOffice Awaits Fix

LibreOffice has fixed a vulnerability that can allow a malicious Calc spreadsheet to execute attacker-controlled Java code when the file is opened, without displaying the macro warning users might expect. The issue is tracked as CVE-2026-63277 and was addressed in LibreOffice updates released on October 5: versions 26.2.5 and 26.8.0.
Apache OpenOffice is affected by a matching issue, CVE-2026-59265. All releases through the current version, 4.1.16, are vulnerable. Apache OpenOffice says a fix is expected in version 4.1.17, which remains under testing.
How the spreadsheet chain reaches Java code
The proof of concept relies on Calc database ranges, a legitimate feature that lets a block of cells retrieve data from an external source and refresh automatically. A spreadsheet can identify an external ODB database file through a web address, causing the office application to download that file when the spreadsheet opens.
The downloaded ODB file can specify a Java Database Connectivity, or JDBC, driver and identify where its code is located. That code may be provided in a JAR archive or from a remote server. With Java support enabled, LibreOffice or OpenOffice can retrieve and start the driver inside the application process.
Researchers demonstrated the path by launching the Calculator application, but stated that an attacker could use it to run arbitrary Java code. The demonstration was tested on Windows and Linux, indicating that the technique is not confined to one operating system. The sample files were kept locally for the demonstration, although an operational attack could host the ODB file and Java code on infrastructure controlled by an attacker.
Normal features combine without a trust prompt
Database ranges, ODB files, JDBC drivers and Java archives are individually supported capabilities. The security problem arises from their combination: the document-triggered refresh path can lead to code execution without the consent prompt normally associated with macros.
Rick de Jager of the V12 security team and Thomas Rinsma and Edoardo Geraci of Codean Labs independently reported the LibreOffice flaw. Apache OpenOffice credits Codean Labs for the corresponding OpenOffice issue. V12 published a proof of concept for both applications, while Caolán McNamara of Collabora Productivity authored the LibreOffice fix.
Actions for office software administrators
LibreOffice deployments should be updated to 26.2.5 or 26.8.0, as versions before those releases are affected. Apache OpenOffice users should disable Java in the application settings until 4.1.17 is available, or avoid opening spreadsheets from untrusted sources.
For businesses, the incident is a reminder that spreadsheet intake policies must account for document features beyond visible macros: patch the office suite, limit Java where it is unnecessary, and ensure employees do not treat externally supplied spreadsheets as passive files.

