LIBREOFFICE has fixed a flaw that could let a malicious spreadsheet run attacker code when opened, without showing a macro warning. The issue arises when Calc spreadsheets use a “database range” that can pull data from an external source (an ODB file) and refresh automatically. The ODB can point to a JDBC driver and a Java class (JAR) containing the attacker’s code, which would then be executed inside the application.
The vulnerability requires Java support to be enabled and, at present, has only been demonstrated as a proof of concept rather than in true malicious campaigns.
The fix for LibreOffice is tracked as CVE-2026-63277 and was released on 5 October 2026; users are advised to update to version 26.2.5 or 26.8.0 (earlier builds remain vulnerable). Apache OpenOffice has a matching flaw, CVE-2026-59265, affecting all versions up to and including 4.1.16; a fix is anticipated in 4.1.17 during testing. For now, OpenOffice users can block the attack by turning off Java in the program’s settings or by avoiding spreadsheets from untrusted sources.
The researchers’ PoC for both programmes is available, and LibreOffice’s fix was authored by Caolán McNamara of Collabora Productivity. The attack has been demonstrated on Windows and Linux and is not OS‑pecific.