Full Report
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro. The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in
Analysis Summary
# Vulnerability: LibreOffice and OpenOffice Remote Code Execution via Malicious JDBC Drivers
## CVE Details
- **CVE ID**: CVE-2026-63277 (LibreOffice), CVE-2026-59265 (Apache OpenOffice)
- **CVSS Score**: Not specifically listed in the article (High severity implied by RCE)
- **CWE**: Not specified (Likely CWE-829: Inclusion of Functionality from Untrusted Control Sphere)
## Affected Systems
- **Products**: LibreOffice, Apache OpenOffice
- **Versions**:
- **LibreOffice**: Versions prior to 26.2.5 and 26.8.0.
- **Apache OpenOffice**: All versions up to and including 4.1.16.
- **Configurations**: The attack requires **Java support** to be enabled within the office suite settings.
## Vulnerability Description
The vulnerability stems from the way "database ranges" refresh in spreadsheet applications. A malicious Calc spreadsheet can define a database range that points to an external ODB (OpenDocument Database) file via a URL. When the spreadsheet is opened, it automatically attempts to refresh this range.
The ODB file can specify a Java Database Connectivity (JDBC) driver and point to a remote JAR file. The application then downloads the JAR and executes the driver code without triggering the standard macro security warnings. By chaining these legitimate features, an attacker achieves arbitrary code execution (RCE) simply by the user opening the file.
## Exploitation
- **Status**: Proof of Concept (PoC) available; not yet reported in the wild.
- **Complexity**: Medium (requires crafting a malicious ODB and hosting a JAR).
- **Attack Vector**: Network (Remote file download triggered upon opening a local or remote document).
## Impact
- **Confidentiality**: High (Attacker can execute code to exfiltrate data).
- **Integrity**: High (Attacker can modify system files or application data).
- **Availability**: High (Attacker can execute destructive code or crash the system).
## Remediation
### Patches
- **LibreOffice**: Update to version **26.2.5** or **26.8.0** or later.
- **Apache OpenOffice**: A fix is expected in version **4.1.17** (currently in testing).
### Workarounds
- **Disable Java**: In the program settings, disable Java support to break the attack chain.
- **Trusted Sources**: Do not open spreadsheet files from untrusted or unknown sources.
## Detection
- **Indicators of Compromise**:
- Outbound connections from `soffice.bin` or `soffice.exe` to unknown remote servers on ports typically used for HTTP/HTTPS (to fetch ODB/JAR files).
- Creation of unexpected Java processes by the office suite.
- **Detection Methods**: Monitor network logs for unusual URL requests originating from office applications, specifically those ending in `.odb` or `.jar`.
## References
- **Vendor Advisories**:
- LibreOffice Security: hxxps://www[.]libreoffice[.]org/security/
- Apache OpenOffice Mailing List: hxxps://www[.]openwall[.]com/lists/oss-security/2026/10/02/2
- **Relevant Links**:
- V12 Security PoC: hxxps://github[.]com/v12-security/pocs/tree/main/office_jdbc_bugs
- Researcher Demo: hxxps://x[.]com/v12sec/status/2107142692853469503