CVE-2026-63277

Announced: Oct 5, 2026

Fixed in: LibreOffice 26.2.5/26.8.0

Description:

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document.

A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location.

In fixed versions an entry in a Java class path has to be a file URL.

All users are recommended to upgrade to LibreOffice >= 26.2.5 or >= 26.8.0 to avoid this problem.

Credits:

Thanks to Rick de Jager of the V12 security team, and to Thomas Rinsma and Edoardo Geraci from Codean Labs, for independently reporting this issue.

Thanks to Caolán McNamara of Collabora Productivity for providing the fix.

References:

CVE-2026-63277