{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-3DA258EF",
  "slug": "cve-2026-63277-libreoffice-calc-external-data-jdbc-rce",
  "title": "Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)",
  "aliases": [
    "CVE-2026-63277",
    "CVE-2026-63266",
    "CVE-2026-63267",
    "CVE-2026-63268",
    "CVE-2026-63269",
    "CVE-2026-63270",
    "LibreOffice 26.2.5 security release",
    "calcext:data-mappings"
  ],
  "summary": "The Document Foundation fixed six LibreOffice bugs on 2026-10-05 in 26.2.5 and 26.8.0. All stem from Calc external data links saved in the document (calcext:data-mappings) that were honored while the document loaded. CVE-2026-63277 lets a document name a Java database (JDBC) driver to be loaded from a remote location, so opening the file could run that Java code (CNA CVSS 4.0 8.5, CWE-829). Siblings: 63266 file write via embedded Firebird backup, 63267 local file read and GET SSRF via the csv provider, 63268 local text file read via the sql provider, 63269 local file read and SSRF via GStreamer HLS playlists on Linux, 63270 environment/INI value exfiltration via XForms and the csv/sql providers (gap in the CVE-2024-12426 check). Highest exposure: servers that open untrusted documents automatically (headless soffice conversion, previews, mail pipelines).",
  "status": "published",
  "severity": "high",
  "confidence": "high",
  "uncertainty": "CVE records list only the 26.2 series below 26.2.5 as affected and mark other versions defaultStatus unknown, so older branches are not confirmed safe. Whether every distro package backport covers all six IDs is per-distro. No exploitation reported in the advisory; not on CISA KEV as of catalog 2026.10.04.",
  "firstObservedAt": "2026-10-05T11:17:20.739Z",
  "lastObservedAt": "2026-10-05T13:23:21.599Z",
  "publishedAt": "2026-10-05T13:29:44.003Z",
  "reviewedAt": "2026-10-05T13:29:29.717Z",
  "expiresAt": "2026-10-05T13:23:21.599Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "lo-63277",
      "label": "LibreOffice advisory CVE-2026-63277",
      "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2026-63277",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-10-05T00:00:00.000Z"
    },
    {
      "id": "lo-63266",
      "label": "LibreOffice advisory CVE-2026-63266",
      "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2026-63266",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-10-05T00:00:00.000Z"
    },
    {
      "id": "lo-63267",
      "label": "LibreOffice advisory CVE-2026-63267",
      "url": "https://www.libreoffice.org/about-us/security/advisories/cve-2026-63267",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-10-05T00:00:00.000Z"
    },
    {
      "id": "cve-63277",
      "label": "CVE-2026-63277 record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63277",
      "sourceType": "vulnerability_database",
      "observedAt": "2026-10-05T11:17:20.739Z"
    },
    {
      "id": "hol-blog",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-63277-libreoffice-calc-external-data-jdbc-rce",
      "sourceType": "other_primary",
      "observedAt": "2026-10-05T13:23:21.599Z"
    }
  ],
  "artifacts": [
    {
      "id": "libreoffice",
      "artifactClass": "package",
      "ecosystem": "desktop-application",
      "name": "LibreOffice",
      "version": "26.2 series before 26.2.5 (CNA); fixed in 26.2.5 and 26.8.0",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "advisories",
      "occurredAt": "2026-10-05T00:00:00.000Z",
      "eventType": "disclosure",
      "summary": "The Document Foundation announced six advisories addressed in LibreOffice 26.2.5/26.8.0.",
      "sourceIds": [
        "lo-63277",
        "lo-63266",
        "lo-63267"
      ]
    },
    {
      "id": "cve-published",
      "occurredAt": "2026-10-05T11:17:20.739Z",
      "eventType": "disclosure",
      "summary": "CVE-2026-63277 published with CVSS 4.0 8.5 (AV:L, UI:P) and CWE-829.",
      "sourceIds": [
        "cve-63277"
      ]
    },
    {
      "id": "hol-blog",
      "occurredAt": "2026-10-05T13:23:21.599Z",
      "eventType": "other",
      "summary": "HOL Guard published operator write-up on hol.org/blog.",
      "sourceIds": [
        "hol-blog"
      ]
    }
  ],
  "coverage": [
    {
      "assertionId": "desktop-app-document-parsing",
      "relationship": "not_covered",
      "limitation": "LibreOffice document loading happens inside the office application, outside Guard Desktop/Inbox agent tool-call interception. The campaign tracks the issue for AEO/SEO; Guard does not claim to block malicious Calc data links."
    }
  ],
  "policies": [],
  "limitations": [
    "CVE-2026-63277 code execution needs a Java runtime available to LibreOffice; the other five do not need Java.",
    "CVE-2026-63269 is tied to GStreamer media playback on Linux.",
    "Not network-reachable: CNA vectors are AV:L with user interaction; a person or pipeline must open the file.",
    "Older branches are marked unknown, not unaffected, in the CVE records."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-63277-libreoffice-calc-external-data-jdbc-rce/corrections"
}
