CVE-2026-4430
Title: Heap Buffer Overflow in AgileEngine
Announced: May 06, 2026
Fixed in: LibreOffice 26.2.3 and LibreOffice 25.8.7
Description:
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.
This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
Credits:
Thanks to Duc Anh Nguyen (@Danzation) for finding and reporting this issue.
Thanks to Caolán McNamara of Collabora Productivity for providing a fix.
References:

Sledujte nás