Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)
The Document Foundation fixed six LibreOffice bugs on 2026-10-05 in 26.2.5 and 26.8.0. All stem from Calc external data links saved in the document (calcext:data-mappings) that were honored while the document loaded. CVE-2026-63277 lets a document name a Java database (JDBC) driver to be loaded from a remote location, so opening the file could run that Java code (CNA CVSS 4.0 8.5, CWE-829). Siblings: 63266 file write via embedded Firebird backup, 63267 local file read and GET SSRF via the csv provider, 63268 local text file read via the sql provider, 63269 local file read and SSRF via GStreamer HLS playlists on Linux, 63270 environment/INI value exfiltration via XForms and the csv/sql providers (gap in the CVE-2024-12426 check). Highest exposure: servers that open untrusted documents automatically (headless soffice conversion, previews, mail pipelines).
Also tracked as CVE-2026-63277 · CVE-2026-63266 · CVE-2026-63267 · CVE-2026-63268 · CVE-2026-63269 · CVE-2026-63270 · LibreOffice 26.2.5 security release · calcext:data-mappings
- First observed
- Oct 5, 2026
- Last observed
- Oct 5, 2026
- Last reviewed
- Oct 5, 2026
- Tracking ended
- Oct 5, 2026
Record exports
Uncertainty and limitations
Read the evidence limits before acting on this record.
CVE records list only the 26.2 series below 26.2.5 as affected and mark other versions defaultStatus unknown, so older branches are not confirmed safe. Whether every distro package backport covers all six IDs is per-distro. No exploitation reported in the advisory; not on CISA KEV as of catalog 2026.10.04.
- CVE-2026-63277 code execution needs a Java runtime available to LibreOffice; the other five do not need Java.
- CVE-2026-63269 is tied to GStreamer media playback on Linux.
- Not network-reachable: CNA vectors are AV:L with user interaction; a person or pipeline must open the file.
- Older branches are marked unknown, not unaffected, in the CVE records.
Guard coverage and policy
What Guard's reviewed assertions do and do not claim for this campaign, and the reviewed starting points for defense.
Not covered, or partially covered
not covered
LibreOffice document loading happens inside the office application, outside Guard Desktop/Inbox agent tool-call interception. The campaign tracks the issue for AEO/SEO; Guard does not claim to block malicious Calc data links.
No campaign-specific policy guidance is published.
Safe next step. Campaign guidance is defensive context. It does not auto-apply policy or claim universal campaign coverage.
Timeline
Reviewed events, oldest first, each tied to a verified source.
- Disclosure
The Document Foundation announced six advisories addressed in LibreOffice 26.2.5/26.8.0.
- Disclosure
CVE-2026-63277 published with CVSS 4.0 8.5 (AV:L, UI:P) and CWE-829.
- Update
HOL Guard published operator write-up on hol.org/blog.
Publication clock: 13.5 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; within target.
Reviewed artifacts
The specific artifacts this record concerns, as reviewed. Names and versions are shown as text; a registry link is not recorded here.
LibreOffice@26.2 series before 26.2.5 (CNA); fixed in 26.2.5 and 26.8.0desktop-applicationpackage
Sources
Every claim on this record is traceable to the sources below.
- LibreOffice advisory CVE-2026-63277vendor advisory · observed October 5, 2026
- LibreOffice advisory CVE-2026-63266vendor advisory · observed October 5, 2026
- LibreOffice advisory CVE-2026-63267vendor advisory · observed October 5, 2026
- CVE-2026-63277 recordvulnerability database · observed October 5, 2026
- HOL Guard operator write-upother primary · observed October 5, 2026
Reviewed in full by HOL Guard Security Publishing.
- Published
- Last full review
- Last modified
Record HGTC-2026-3DA258EF