LibreOffice fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5.
What the bug does and why it matters
Security researchers demonstrated that a crafted spreadsheet can make LibreOffice and Apache OpenOffice execute an attacker’s Java code the moment the file is opened — and without the macro warning the programs normally show. The attack requires that the program’s Java support be enabled. So far the behavior has been shown only as a proof of concept and there are no public reports that the technique has been used in the wild.
How the attack chain works
The researchers combined several legitimate features to produce the path to code execution. A Calc spreadsheet can contain a “database range,” a block of cells that pulls data from an external source and refreshes automatically. That source can be an ODB database file named by a web address embedded in the spreadsheet.
When the spreadsheet opens, the database range refreshes and the program downloads the ODB from that URL. The ODB can specify a Java database driver (a JDBC driver) and point to where the driver’s code lives — typically a JAR file. The program then downloads that JAR and starts the driver inside the application. In the proof of concept the driver simply launched the Calculator application, but the same mechanism can run any Java code placed in the JAR.
Individually, each step is an intended feature; the security problem, the researchers say, is that together they reach code execution without ever prompting the user to trust the document the way a macro prompt would.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleLibreOffice response: CVE-2026-63277 and patched versions
LibreOffice released updates on October 5 that address the flaw tracked as CVE-2026-63277 and recommends users move to version 26.2.5 or 26.8.0. The fix was written by Caolán McNamara of Collabora Productivity. The vulnerability was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs; the V12 team has published a proof of concept for both programs.
Apache OpenOffice: CVE-2026-59265, mitigation, and the patch timeline
Apache OpenOffice has a matching flaw tracked as CVE-2026-59265. Every version up to and including the current release, 4.1.16, is affected. The Apache OpenOffice project says a fix is expected in version 4.1.17, which is still being tested. Apache credits Codean Labs for the matching OpenOffice flaw.
Until 4.1.17 ships, Apache OpenOffice users can block the attack by turning off Java in the program’s settings, or by not opening spreadsheets they do not trust — the project explicitly lists those two mitigations.
Proof-of-concept testing and attacker model
The published proof of concept ran the same path on both Windows and Linux and used the Calculator app as a harmless demonstration. In the researchers’ demonstration the malicious ODB and JAR files resided on the same machine for convenience; the report states that a real-world attack would instead place the database file and the driver code on an attacker-controlled server so the spreadsheet would fetch them over the network.
What this means for technologists, end users, and open-source maintainers
- Technologists and security teams: apply LibreOffice updates to move to 26.2.5 or 26.8.0 where available, and for Apache OpenOffice consider disabling Java until 4.1.17 is released or block untrusted spreadsheets at email and gateway layers.
- End users: avoid opening spreadsheets from untrusted sources and, if you use Apache OpenOffice, turn off Java in the program’s settings to prevent the automatic fetch-and-execute path the proof of concept exploits.
- Open-source maintainers: the disclosures were credited to multiple researchers and teams — Codean Labs and the V12 security team — and the fix process shows a split timeline between projects; Apache OpenOffice continues testing its 4.1.17 release while LibreOffice has already pushed updates.
The vulnerability is notable for what it reveals about composability: ordinary features—database ranges, remote ODBs and the ability to load JDBC drivers—can be combined into a silent execution path when Java is available. LibreOffice has moved to patch that path; Apache OpenOffice is testing its fix but remains exposed until 4.1.17 is released. The Hacker News has contacted The Document Foundation and the Apache OpenOffice project for comment.




