high severityConfidence highHistorical record

Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)

The Document Foundation fixed six LibreOffice bugs on 2026-10-05 in 26.2.5 and 26.8.0. All stem from Calc external data links saved in the document (calcext:data-mappings) that were honored while the document loaded. CVE-2026-63277 lets a document name a Java database (JDBC) driver to be loaded from a remote location, so opening the file could run that Java code (CNA CVSS 4.0 8.5, CWE-829). Siblings: 63266 file write via embedded Firebird backup, 63267 local file read and GET SSRF via the csv provider, 63268 local text file read via the sql provider, 63269 local file read and SSRF via GStreamer HLS playlists on Linux, 63270 environment/INI value exfiltration via XForms and the csv/sql providers (gap in the CVE-2024-12426 check). Highest exposure: servers that open untrusted documents automatically (headless soffice conversion, previews, mail pipelines).

Also tracked as CVE-2026-63277 · CVE-2026-63266 · CVE-2026-63267 · CVE-2026-63268 · CVE-2026-63269 · CVE-2026-63270 · LibreOffice 26.2.5 security release · calcext:data-mappings

First observed
Oct 5, 2026
Last observed
Oct 5, 2026
Last reviewed
Oct 5, 2026
Tracking ended
Oct 5, 2026

Uncertainty and limitations

Read the evidence limits before acting on this record.

CVE records list only the 26.2 series below 26.2.5 as affected and mark other versions defaultStatus unknown, so older branches are not confirmed safe. Whether every distro package backport covers all six IDs is per-distro. No exploitation reported in the advisory; not on CISA KEV as of catalog 2026.10.04.

  • CVE-2026-63277 code execution needs a Java runtime available to LibreOffice; the other five do not need Java.
  • CVE-2026-63269 is tied to GStreamer media playback on Linux.
  • Not network-reachable: CNA vectors are AV:L with user interaction; a person or pipeline must open the file.
  • Older branches are marked unknown, not unaffected, in the CVE records.

Guard coverage and policy

What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.

Not covered, or partially covered

  • not covered

    LibreOffice document loading happens inside the office application, outside Guard Desktop/Inbox agent tool-call interception. The campaign tracks the issue for AEO/SEO; Guard does not claim to block malicious Calc data links.

No campaign-specific policy guidance is published.

Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.

Timeline

Reviewed events, oldest first, each tied to a verified source.

  1. Disclosure

    The Document Foundation announced six advisories addressed in LibreOffice 26.2.5/26.8.0.

  2. Disclosure

    CVE-2026-63277 published with CVSS 4.0 8.5 (AV:L, UI:P) and CWE-829.

  3. Update

    HOL Guard published operator write-up on hol.org/blog.

Publication clock: 13.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; within target.

Reviewed artifacts

The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.

  • LibreOffice@26.2 series before 26.2.5 (CNA); fixed in 26.2.5 and 26.8.0desktop-applicationpackage

Sources

Every claim on this record is traceable to the sources below.

Reviewed in full by HOL Guard Security Publishing.

Published
Last full review
Last modified

Report a correction

Record HGTC-2026-3DA258EF