Skip to content

LibreOffice RCE via JDBC runs code with no macro warning

CVE-2026-63277 lets a crafted LibreOffice Calc document load a remote Java driver and run code on open — no macro prompt. Fixed in 26.2.5 and 26.8.0.

Published 3 min read

A crafted LibreOffice Calc document can run arbitrary Java code the moment it opens — with no macro-security prompt. Tracked as CVE-2026-63277, the flaw was fixed on October 5 in LibreOffice 26.2.5 and 26.8.0, per the LibreOffice security advisory. A parallel flaw in Apache OpenOffice is tracked as CVE-2026-59265. Proof-of-concept exists; no in-the-wild exploitation has been reported.

What the bug does

LibreOffice Calc can link cell ranges to external data sources through its SQL provider and JDBC connector. The advisory describes the problem verbatim: "A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location." Because the trigger is the external-data link mechanism — not a macro — the user never sees the macro-security warning that normally gates document code execution.

The fix constrains where drivers can load from. Per the advisory: "In fixed versions an entry in a Java class path has to be a file URL." Remote class-path entries are no longer honored.

Affected and fixed

  • LibreOffice — versions before 26.2.5 and 26.8.0. Fixed October 5, 2026. See the NVD entry.
  • Apache OpenOffice — all versions up to and including 4.1.16 are affected by the parallel CVE-2026-59265 (NVD); the fix lands in 4.1.17. France's CERT-FR covered the OpenOffice side in avis CERTFR-2026-AVI-1260.

The flaw was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. The fix was authored by Caolán McNamara of Collabora Productivity.

Exploitation status

No active exploitation is reported. A PoC exists, which shortens the window between disclosure and opportunistic use — a spreadsheet that fires on open, with no macro prompt, is an attractive phishing payload. Treat inbound ODS/XLSX attachments as untrusted until users are patched.

Action checklist

  1. Update LibreOffice to 26.2.5 or 26.8.0 (or later) on every endpoint. Both the 26.2 and 26.8 lines carry the fix.
  2. For OpenOffice users, plan migration to 4.1.17 when it ships; until then, do not open spreadsheets from untrusted sources, and consider disabling Java in the office suite (Tools → Options → Advanced).
  3. Block or quarantine inbound spreadsheet attachments at the mail gateway for unpatched populations.
  4. Prioritize shared/multi-user workstations and any environment where documents arrive from outside the org.

Context

This is a macro-less document-to-code path, the category that defeats the "don't enable macros" guidance every security-awareness program teaches. The trigger is a legitimate feature — external-data links via JDBC — turned into a remote code loader. Office-suite document parsers remain a durable initial-access surface; the mitigation that matters here is the patch, because user training does not help when there is no prompt to ignore.

Related stories