Security researchers have uncovered a critical security vulnerability affecting two of the world’s most popular open-source office suites, LibreOffice and Apache OpenOffice. The flaw allows a maliciously crafted spreadsheet to execute arbitrary attacker-controlled code immediately upon being opened by a victim, completely bypassing the traditional security warnings that users normally encounter before macros or scripts are executed.

Discovered and demonstrated as a working proof of concept, the vulnerability highlights the risks inherent in complex software integrations where individual, legitimate features can be chained together in unintended ways. While the flaw currently requires the target application’s Java support to be explicitly enabled, it presents a significant vector for remote code execution across multiple operating systems, including Windows and Linux. Security patches and temporary mitigations have been released or proposed as developers race to secure their respective user bases.

The Threat Vector and Mechanics of the Attack

The core of the vulnerability does not rely on a single software bug or a memory corruption error. Instead, it represents a sophisticated exploitation of standard, intended features operating in tandem within the spreadsheet components of LibreOffice Calc and Apache OpenOffice Calc.

Both applications support a feature known as a "database range," which is a defined block of cells designed to pull in data from an external source and refresh that information automatically. Normally, this allows users to keep their spreadsheets synchronized with separate database files—specifically OpenDatabase (ODB) files—by referencing a web address directly within the spreadsheet structure.

When an unsuspecting user opens a malicious spreadsheet containing this setup, the application automatically attempts to refresh the database range. In doing so, it downloads the ODB file from the specified remote web address.

The security breakdown occurs because the ODB file can be configured to point to a Java database driver, commonly referred to as a JDBC driver. Furthermore, the file can dictate the precise location of the driver’s underlying code, which may reside within a JAR file hosted on a remote server under the attacker’s control.

Upon reading these instructions, the office suite automatically downloads the remote JAR file and initializes the driver directly within the application’s memory space, effectively executing the attacker’s code. Because each of these steps—database ranges, remote data fetching, and JDBC driver loading—functions exactly as designed by the developers, the software treats the process as routine data handling. Crucially, the program fails to prompt the user to trust the document or verify the origin of the embedded code, bypassing the standard warning dialog boxes that typically appear when a document attempts to run macro scripts.

Proof of Concept and Cross-Platform Impact

To demonstrate the viability of the attack, security researchers created a functional proof of concept. In their demonstration, the malicious driver executed a relatively benign action by launching the native Calculator application on the host machine. However, researchers emphasize that the same execution path can be leveraged to run any arbitrary Java code chosen by an attacker, ranging from data exfiltration scripts to persistent malware payloads.

Extensive testing conducted by the researchers confirmed that the vulnerability is not restricted to a single operating system. Successful exploitation was verified across both Windows and Linux environments, demonstrating that the underlying mechanism affects the core codebase of the office suites rather than OS-specific APIs.

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

In their initial laboratory demonstrations, the researchers placed the necessary database files and payload components on the local machine for convenience. They noted, however, that a real-world exploitation scenario would involve hosting the ODB file and the accompanying Java archive on an attacker-controlled remote server, allowing for seamless remote attacks against targeted individuals or organizations.

Patch Status and Developer Responses

The discovery of the vulnerability triggered coordinated reporting and response efforts among security researchers and software maintainers.

The flaw affecting LibreOffice has been officially tracked under the identifier CVE-2026-63277. The vulnerability was reported independently to LibreOffice developers by Rick de Jager of the V12 security team, alongside Thomas Rinsma and Edoardo Geraci of Codean Labs. Swift action from the development community led to a security update authored by Caolán McNamara of Collabora Productivity.

LibreOffice published official fixes for the issue on October 5, urging all users to upgrade to version 26.2.5 or version 26.8.0 to protect against potential exploitation. All preceding versions of LibreOffice are considered vulnerable if Java support is enabled.

Meanwhile, the matching flaw in Apache OpenOffice is tracked under CVE-2026-59265, with Apache crediting Codean Labs for the initial identification and report. Unlike LibreOffice, the Apache OpenOffice project has not yet released a finalized patch. Every version of Apache OpenOffice up to and including the current 4.1.16 release remains affected by the vulnerability.

The Apache OpenOffice project has indicated that a permanent fix is expected to be included in version 4.1.17, which is currently undergoing internal testing and quality assurance.

Until the updated version is officially released and deployed, Apache OpenOffice users have been advised to implement temporary defensive measures. Administrators and individual users can neutralize the threat vector by disabling Java support entirely within the application’s configuration settings or by strictly avoiding spreadsheets received from untrusted or unknown sources.

The V12 security team has publicly released a proof of concept detailing the mechanics of the flaw for both office suites, providing security professionals with the means to test their environments and verify protections as the broader open-source community works to deploy comprehensive updates.

Leave a Reply

Your email address will not be published. Required fields are marked *