LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Execute Code Without Macro Warnings
Critical LibreOffice and Apache OpenOffice vulnerabilities allow malicious spreadsheets to execute Java code without macro warnings. LibreOffice users should update, while OpenOffice users should disable Java until a fix is released.

Security researchers have disclosed critical vulnerabilities affecting LibreOffice and Apache OpenOffice that could allow a malicious spreadsheet to execute attacker-controlled Java code simply when a victim opens the document.
The attack is particularly concerning because it can execute code without displaying the macro security warning users would normally expect before potentially dangerous document code runs.
Vulnerabilities at a Glance
| Product | CVE | Status |
|---|---|---|
| LibreOffice | CVE-2026-63277 | Fixed |
| Apache OpenOffice | CVE-2026-59265 | Fix pending |
| LibreOffice Fixed Versions | 26.2.5 / 26.8.0 | Available |
| OpenOffice Affected Versions | 4.1.16 and earlier | Vulnerable |
| OpenOffice Fix | 4.1.17 | Release candidate |
| Requirement | Java support enabled | Required |
| Active Exploitation | None reported | PoC available |
LibreOffice released fixes on October 5, while Apache says its corresponding issue is expected to be addressed in OpenOffice 4.1.17.
How the Attack Works
The vulnerabilities abuse legitimate functionality in Calc, the spreadsheet application included with both office suites.
Calc supports database ranges that allow spreadsheets to retrieve information from external data sources. A malicious spreadsheet can configure such a range to reference an external OpenDocument Database (.odb) file.
That database can then specify a Java Database Connectivity (JDBC) driver and tell the office application where to retrieve the associated Java code.
Researchers found that this could be abused to load a malicious JAR file from an attacker-controlled location.
The attack chain looks like:
Malicious Spreadsheet → External ODB File → JDBC Driver → Remote JAR Download → Java Code Execution
Because the execution occurs through database and Java functionality rather than a traditional document macro, the normal macro-warning mechanism does not protect the user.
Proof-of-Concept Demonstrates Code Execution
Researchers developed a proof-of-concept demonstrating the vulnerability on Windows and Linux.
Instead of deploying malware, the demonstration launches the operating system's calculator application—a standard security-research technique for proving arbitrary code execution.
A real attacker could potentially replace the harmless demonstration payload with malicious Java code.
Java Must Be Enabled
The attack has an important prerequisite: Java support must be installed and enabled within LibreOffice or OpenOffice.
Systems where Java integration is disabled are not vulnerable through this specific attack path.
This significantly affects the practical attack surface, but organizations with Java-enabled office deployments should still treat the issue seriously.
LibreOffice Users Should Update Now
The Document Foundation has fixed CVE-2026-63277 in:
- LibreOffice 26.2.5
- LibreOffice 26.8.0
The fix restricts Java class-path entries so that they must use file URLs, preventing documents from instructing LibreOffice to retrieve Java classes from arbitrary remote locations.
LibreOffice users should upgrade to 26.2.5, 26.8.0 or later.
OpenOffice Remains Vulnerable
The corresponding Apache OpenOffice vulnerability is tracked separately as CVE-2026-59265 and is classified by Apache as Critical.
All Apache OpenOffice versions through 4.1.16 are affected.
Apache expects the vulnerability to be fixed in OpenOffice 4.1.17, which was still in the release-candidate stage at the time of disclosure.
Until the update becomes available, Apache recommends disabling Java:
Tools → Options → OpenOffice → Java → Disable “Use a Java runtime environment”
On macOS, the corresponding setting is available through the application's Preferences. Users should also avoid opening spreadsheets from untrusted sources.
More LibreOffice Security Flaws Patched
LibreOffice 26.2.5 and 26.8.0 also address several other vulnerabilities related to external data handling.
These include flaws capable of enabling:
- Arbitrary file writes
- Local file disclosure
- Server-Side Request Forgery (SSRF)
- Environment and INI-file information leakage
The issues include CVE-2026-63266 through CVE-2026-63270, alongside the Java code-execution vulnerability CVE-2026-63277.
Security Takeaway
The vulnerabilities demonstrate that malicious documents do not necessarily need traditional macros to achieve code execution.
In this case, attackers can potentially abuse legitimate spreadsheet database functionality:
Open Spreadsheet → Retrieve External Database → Load Remote Java Driver → Execute Attacker Code
Organizations should therefore treat unexpected office documents as potential attack vectors even when they contain no macros.
LibreOffice users should immediately upgrade to a patched release. OpenOffice users should disable Java integration until version 4.1.17 or another fixed release is installed.
There are currently no reports of these vulnerabilities being exploited in real-world attacks, although public proof-of-concept research is available.
Related reporting
Google Pauses Open-Source Product Bug Bounties After Surge in Invalid Automated Reports
Google pauses product vulnerability submissions to its OSS bug bounty program after a surge in invalid automated reports, while supply-chain reports and existing submissions remain unaffected.
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Files Across Eight Products
Atlassian patches CVE-2026-21589, a critical CVSS 9.3 flaw allowing unauthenticated attackers to access known files across Jira, Confluence, Bitbucket and five other Data Center products.
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users’ Mailboxes
Microsoft patches CVE-2026-96940, a high-severity Exchange Server flaw that could let authenticated attackers access other users' mailboxes, emails and attachments.


