{"type":"bundle","id":"bundle--763397c5-5c96-5554-b30d-67176758603b","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--2b257619-b577-5697-882d-f6e8ef413b0a","created":"2026-10-05T13:29:44.003Z","modified":"2026-10-05T13:29:44.003Z","name":"Opening a LibreOffice spreadsheet can run remote Java code (CVE-2026-63277)","description":"The Document Foundation fixed six LibreOffice bugs on 2026-10-05 in 26.2.5 and 26.8.0. All stem from Calc external data links saved in the document (calcext:data-mappings) that were honored while the document loaded. CVE-2026-63277 lets a document name a Java database (JDBC) driver to be loaded from a remote location, so opening the file could run that Java code (CNA CVSS 4.0 8.5, CWE-829). Siblings: 63266 file write via embedded Firebird backup, 63267 local file read and GET SSRF via the csv provider, 63268 local text file read via the sql provider, 63269 local file read and SSRF via GStreamer HLS playlists on Linux, 63270 environment/INI value exfiltration via XForms and the csv/sql providers (gap in the CVE-2024-12426 check). Highest exposure: servers that open untrusted documents automatically (headless soffice conversion, previews, mail pipelines).","aliases":["CVE-2026-63277","CVE-2026-63266","CVE-2026-63267","CVE-2026-63268","CVE-2026-63269","CVE-2026-63270","LibreOffice 26.2.5 security release","calcext:data-mappings"],"first_seen":"2026-10-05T11:17:20.739Z","last_seen":"2026-10-05T13:23:21.599Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"LibreOffice advisory CVE-2026-63277","url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-63277"},{"source_name":"LibreOffice advisory CVE-2026-63266","url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-63266"},{"source_name":"LibreOffice advisory CVE-2026-63267","url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-63267"},{"source_name":"CVE-2026-63277 record","url":"https://www.cve.org/CVERecord?id=CVE-2026-63277"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-63277-libreoffice-calc-external-data-jdbc-rce"}]}]}