Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)

How to fix CVE-2026-63277: upgrade LibreOffice to 26.2.5 or 26.8.0. A saved Calc external data link could load a remote Java driver on open; five sibling file-read, file-write and SSRF bugs are fixed in the same release.

5 min read1,094 words
Contents

A spreadsheet someone sends you can tell LibreOffice Calc to fetch a Java database driver from a server they control and run it, the moment the file opens. That is CVE-2026-63277, and it is the worst of six bugs The Document Foundation fixed on 2026-10-05 in LibreOffice 26.2.5 and 26.8.0. All six come from the same place: a Calc feature that saves a link to an external data source inside the document, and then honored that link while the document loaded.

Thomas Rinsma and Edoardo Geraci of Codean Labs reported the batch. Rick de Jager of the V12 security team found the JDBC driver bug independently. Caolán McNamara of Collabora Productivity wrote the fixes. This post is our operator read of the LibreOffice advisories; the HOL Guard evidence pack for CVE-2026-63277 is the source record.

Calc can bind a cell range to outside data (a csv file, a database, a web table). The binding is stored in the file as calcext:data-mappings, so it comes back every time the sheet opens. Before 26.2.5, Calc refreshed those bindings during load, outside the link-update prompt that already guards other external links. Whoever wrote the file chose the data source, the provider, and in one case the code that reads it.

Here is what each bug lets the file do when it opens:

  • CVE-2026-63277: Load a JDBC driver from a remote location and run that Java code (CVSS 4.0 score 8.5 from the CNA).
  • CVE-2026-63266: Open an embedded Firebird database whose backup routine writes a file anywhere your user account can write.
  • CVE-2026-63267: Read a local file into the sheet, or send a GET request to a host the document picks (csv provider).
  • CVE-2026-63268: Point the sql provider at a folder of local text files and read one into the sheet.
  • CVE-2026-63269: On Linux, hand GStreamer an HLS playlist that reads local files and remote URLs while the document loads.
  • CVE-2026-63270: Expand environment variables or INI values into a URL and send them to a remote server (the CVE-2024-12426 check missed XForms and the csv and sql providers).

Put together, a single file can read something private (63267, 63268, 63270) and ship it out, or drop a file into your home directory (63266), or skip straight to running code (63277). The fixed builds close each path separately: only csv, html and xml providers are restored on load, external data follows the normal link-update control, Firebird stays in its private directory, playlists that name further resources are not followed, and a Java class path entry has to be a file: URL.

Where the "open" actually happens

On a desktop, it is you double-clicking an attachment. The bigger exposure is servers that open files for a living. A document-conversion worker that runs soffice --headless --convert-to pdf on uploads, a preview generator in a file-sharing app, or a mail pipeline that renders attachments all load untrusted documents with nobody watching. The advisory says the links fired while the document loaded, and loading is the whole job of a conversion worker. Treat those boxes as first in line.

The same goes for an AI agent on your laptop that shells out to soffice to read a spreadsheet someone emailed. To LibreOffice that is an open like any other.

Who is not in scope

  • Machines with no Java runtime for LibreOffice. A JDBC driver only runs through LibreOffice's Java support. If no JRE is installed, or "Use a Java runtime environment" is unchecked, the 63277 code-execution path has nothing to run on. The other five bugs do not need Java, so this narrows the worst case, not the patch.
  • Windows and macOS for CVE-2026-63269. The advisory ties the HLS playlist bug to GStreamer media playback on Linux.
  • Nobody reaches LibreOffice over the network. The CNA vectors are local with user interaction (AV:L, UI:P). An attacker needs a person or a pipeline to open their file.

One thing that is not a safe assumption: the CVE records list only the 26.2 series below 26.2.5 as affected and mark every other version "unknown," not "unaffected." If you run an older branch, do not read the 26.2-only range as a clean bill. The supported fix is 26.2.5 or 26.8.0.

One operator check

Check the version on every desktop image and every conversion container:

soffice --version
# or
libreoffice --version

# Fixed: LibreOffice 26.2.5 or later, or 26.8.0 or later

To see whether a suspicious .ods carries an external data binding at all, look inside it without opening it in Calc (an .ods is a zip; a .fods is plain XML you can grep directly):

unzip -p suspect.ods content.xml | grep -o 'calcext:data-mapping[^>]*'

A normal budget sheet from a colleague has no reason to bind cells to a remote database or a Java driver. Any hit there is worth a look before you double-click.

How to fix

# Windows (winget)
winget upgrade TheDocumentFoundation.LibreOffice

# macOS (Homebrew cask)
brew upgrade --cask libreoffice

# Linux Flatpak
flatpak update org.libreoffice.LibreOffice

# Or download 26.2.5 / 26.8.0 directly
# https://www.libreoffice.org/download/

# Afterwards, confirm
soffice --version

Distro packages (apt, dnf, zypper) move on their own schedule and often backport fixes without changing to 26.2.5. Check your distribution's security tracker for these CVE IDs before you assume a routine upgrade covered you. Docker-based conversion services need a rebuilt image, not just a restart: run soffice --version inside the new container.

If a conversion worker cannot be upgraded today, these cut the blast radius until it can (our advice, not the vendor's): block outbound network from the worker so remote drivers and exfil URLs go nowhere, leave the JRE out of the image, and run soffice as a throwaway user whose home directory is wiped after each job, so a file written by 63266 lands somewhere that does not matter.

What this is not

This is not a wormable network bug: LibreOffice does not listen on a port, and every one of these needs a document to be opened. It is also not reported as exploited. The advisory does not mention attacks in the wild, and none of the six is on the CISA KEV catalog as of version 2026.10.04.

References

Continue reading

All posts