Skip to main content
The Wire
CyberNews by Zentrya One
critical CVE-2026-63277 Vulnerabilities

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Execute Code Without Macro Warnings

Critical LibreOffice and Apache OpenOffice vulnerabilities allow malicious spreadsheets to execute Java code without macro warnings. LibreOffice users should update, while OpenOffice users should disable Java until a fix is released.

Security researchers have disclosed critical vulnerabilities affecting LibreOffice and Apache OpenOffice that could allow a malicious spreadsheet to execute attacker-controlled Java code simply when a victim opens the document.

The attack is particularly concerning because it can execute code without displaying the macro security warning users would normally expect before potentially dangerous document code runs.

Vulnerabilities at a Glance

Product CVE Status
LibreOffice CVE-2026-63277 Fixed
Apache OpenOffice CVE-2026-59265 Fix pending
LibreOffice Fixed Versions 26.2.5 / 26.8.0 Available
OpenOffice Affected Versions 4.1.16 and earlier Vulnerable
OpenOffice Fix 4.1.17 Release candidate
Requirement Java support enabled Required
Active Exploitation None reported PoC available

LibreOffice released fixes on October 5, while Apache says its corresponding issue is expected to be addressed in OpenOffice 4.1.17.

How the Attack Works

The vulnerabilities abuse legitimate functionality in Calc, the spreadsheet application included with both office suites.

Calc supports database ranges that allow spreadsheets to retrieve information from external data sources. A malicious spreadsheet can configure such a range to reference an external OpenDocument Database (.odb) file.

That database can then specify a Java Database Connectivity (JDBC) driver and tell the office application where to retrieve the associated Java code.

Researchers found that this could be abused to load a malicious JAR file from an attacker-controlled location.

The attack chain looks like:

Malicious Spreadsheet → External ODB File → JDBC Driver → Remote JAR Download → Java Code Execution

Because the execution occurs through database and Java functionality rather than a traditional document macro, the normal macro-warning mechanism does not protect the user.

Proof-of-Concept Demonstrates Code Execution

Researchers developed a proof-of-concept demonstrating the vulnerability on Windows and Linux.

Instead of deploying malware, the demonstration launches the operating system's calculator application—a standard security-research technique for proving arbitrary code execution.

A real attacker could potentially replace the harmless demonstration payload with malicious Java code.

Java Must Be Enabled

The attack has an important prerequisite: Java support must be installed and enabled within LibreOffice or OpenOffice.

Systems where Java integration is disabled are not vulnerable through this specific attack path.

This significantly affects the practical attack surface, but organizations with Java-enabled office deployments should still treat the issue seriously.

LibreOffice Users Should Update Now

The Document Foundation has fixed CVE-2026-63277 in:

  • LibreOffice 26.2.5
  • LibreOffice 26.8.0

The fix restricts Java class-path entries so that they must use file URLs, preventing documents from instructing LibreOffice to retrieve Java classes from arbitrary remote locations.

LibreOffice users should upgrade to 26.2.5, 26.8.0 or later.

OpenOffice Remains Vulnerable

The corresponding Apache OpenOffice vulnerability is tracked separately as CVE-2026-59265 and is classified by Apache as Critical.

All Apache OpenOffice versions through 4.1.16 are affected.

Apache expects the vulnerability to be fixed in OpenOffice 4.1.17, which was still in the release-candidate stage at the time of disclosure.

Until the update becomes available, Apache recommends disabling Java:

Tools → Options → OpenOffice → Java → Disable “Use a Java runtime environment”

On macOS, the corresponding setting is available through the application's Preferences. Users should also avoid opening spreadsheets from untrusted sources.

More LibreOffice Security Flaws Patched

LibreOffice 26.2.5 and 26.8.0 also address several other vulnerabilities related to external data handling.

These include flaws capable of enabling:

  • Arbitrary file writes
  • Local file disclosure
  • Server-Side Request Forgery (SSRF)
  • Environment and INI-file information leakage

The issues include CVE-2026-63266 through CVE-2026-63270, alongside the Java code-execution vulnerability CVE-2026-63277.

Security Takeaway

The vulnerabilities demonstrate that malicious documents do not necessarily need traditional macros to achieve code execution.

In this case, attackers can potentially abuse legitimate spreadsheet database functionality:

Open Spreadsheet → Retrieve External Database → Load Remote Java Driver → Execute Attacker Code

Organizations should therefore treat unexpected office documents as potential attack vectors even when they contain no macros.

LibreOffice users should immediately upgrade to a patched release. OpenOffice users should disable Java integration until version 4.1.17 or another fixed release is installed.

There are currently no reports of these vulnerabilities being exploited in real-world attacks, although public proof-of-concept research is available.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.