CVE-2026-4430

Title: Heap Buffer Overflow in AgileEngine 

Announced: May 06, 2026

Fixed in: LibreOffice 26.2.3 and LibreOffice 25.8.7

Description:

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.

This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

Credits:

Thanks to Duc Anh Nguyen (@Danzation) for finding and reporting this issue.

Thanks to Caolán McNamara of Collabora Productivity for providing a fix.

References:

CVE-2026-4430