# LibreOffice & OpenOffice RCE via Malicious Spreadsheets

> Vulnerabilities in LibreOffice (CVE-2026-63277) and Apache OpenOffice (CVE-2026-59265) allow RCE via malicious spreadsheets without macro warnings.

- Published: 2026-10-06T14:36:04.000Z
- Severity: medium
- Category: Vulnerabilities
- Tags: Remote Code Execution, LibreOffice, Apache OpenOffice, CVE-2026-63277, CVE-2026-59265
- CVEs: CVE-2026-63277, CVE-2026-59265
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
- Canonical: https://runtimerebel.com/blog/libreoffice-openoffice-rce-via-malicious-spreadsheets

## Key points

- Malicious spreadsheets can execute attacker code in LibreOffice and Apache OpenOffice without macro warnings, bypassing standard security prompts.
- Affected systems include LibreOffice versions prior to 26.2.5/26.8.0 and Apache OpenOffice up to 4.1.16, when Java support is enabled.
- Users must update LibreOffice immediately or disable Java support in OpenOffice to prevent potential remote code execution.

## Overview of Malicious Spreadsheet Vulnerabilities

A significant security advisory highlights critical vulnerabilities in widely used office suites, LibreOffice and Apache OpenOffice. These flaws, tracked as [CVE-2026-63277](https://nvd.nist.gov/vuln/detail/CVE-2026-63277) for LibreOffice and [CVE-2026-59265](https://nvd.nist.gov/vuln/detail/CVE-2026-59265) for Apache OpenOffice, allow for remote code execution ([RCE](/glossary#rce)) without the usual macro warning prompts when a malicious spreadsheet is opened. This bypasses a fundamental security mechanism designed to protect users from untrusted code execution.

According to [The Hacker News](https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html), security researchers have demonstrated a proof-of-concept (PoC) for these vulnerabilities, which [exploit](/glossary#exploit) legitimate features to achieve arbitrary code execution. While there are no confirmed reports of these flaws being exploited in the wild, the potential for silent RCE makes them a serious concern for organizations and individual users relying on these productivity tools. The attack relies on the programs' Java support being enabled, a common configuration that many users might have without realizing the security implications.

## Technical Analysis of the RCE Mechanism

The core of these vulnerabilities lies in an ingenious combination of features that, individually, function as intended but collectively create an exploitable chain. Both LibreOffice Calc and Apache OpenOffice Calc spreadsheets support "database ranges." These ranges are blocks of cells configured to pull and refresh data automatically from an external source. Crucially, this external source can be a separate database file (ODB), specified by a web address embedded directly within the spreadsheet.

When a user opens such a malicious spreadsheet, the program attempts to refresh the database range. This action triggers the download of the ODB file from the specified web address, which an attacker can control. The ODB file, in turn, can name a Java Database Connectivity (JDBC) driver and point to the driver's code, typically a Java Archive (JAR) file, which can reside on a remote server. The program then proceeds to download this JAR file and initiate the driver. The critical security oversight here is that the initiated "driver" is, in fact, the attacker's arbitrary Java code, which executes within the context of the office suite application without any user interaction or macro security warning.

### How Attackers Exploit LibreOffice [CVE](/glossary#cve)-2026-63277 and CVE-2026-59265

The researchers demonstrated that this method could be used to execute arbitrary Java code. For example, in their proof-of-concept, the driver simply launched the Calculator application, a harmless action but indicative of full code execution capabilities. The implications are significant, as a real-world attacker could execute any chosen Java code, leading to system compromise, [data exfiltration](/glossary#data-exfiltration), or further [malware](/glossary#malware) deployment. This exploitation method for [CVE-2026-63277](https://nvd.nist.gov/vuln/detail/CVE-2026-63277) and [CVE-2026-59265](https://nvd.nist.gov/vuln/detail/CVE-2026-59265) essentially transforms a seemingly innocuous spreadsheet into a potent [attack vector](/glossary#attack-vector), bypassing traditional security alerts. The vulnerabilities were successfully tested on both Windows and Linux, indicating platform independence. While the proof-of-concept used local files for convenience, a real attack scenario would involve placing the malicious database file and code on an attacker-controlled server.

## Affected Versions and Remediation

Organizations and individual users must identify their current LibreOffice and Apache OpenOffice versions to assess their exposure to these vulnerabilities.

### LibreOffice [Vulnerability](/glossary#vulnerability) and Patching

*   **Affected Versions**: All LibreOffice versions prior to 26.2.5 or 26.8.0 are vulnerable.
*   **Fix**: LibreOffice has already released patches for [CVE-2026-63277](https://nvd.nist.gov/vuln/detail/CVE-2026-63277). Users are strongly advised to update to version 26.2.5 or 26.8.0 (or newer) immediately. The fix was developed by Caolán McNamara of Collabora Productivity.

### Apache OpenOffice 4.1.16 RCE Mitigation

*   **Affected Versions**: Apache OpenOffice remains vulnerable, including all versions up to and including the current release, 4.1.16.
*   **Fix Status**: A fix for [CVE-2026-59265](https://nvd.nist.gov/vuln/detail/CVE-2026-59265) is expected in version 4.1.17, which is currently undergoing testing.
*   **Interim Mitigations**: Until the official [patch](/glossary#patch) is released, users of Apache OpenOffice have two primary options to mitigate the risk:
    *   **Disable Java Support**: Navigate to the program's settings and disable Java functionality. This will prevent the malicious JDBC driver from being loaded and executed.
    *   **Exercise Extreme Caution**: Avoid opening any spreadsheets from untrusted sources. Treat all unsolicited or suspicious spreadsheet files with extreme skepticism.

## Actionable Recommendations for Defenders

Defenders should prioritize these actions to protect against the silent remote code execution risk posed by these vulnerabilities:

*   **Immediate Patching**: For LibreOffice users, apply the latest updates (version 26.2.5, 26.8.0, or higher) without delay. This is the most effective defense against [CVE-2026-63277](https://nvd.nist.gov/vuln/detail/CVE-2026-63277).
*   **Configuration Review**: For Apache OpenOffice users, review and disable Java support within the application settings if it's not strictly required for essential workflows. This is a critical step for Apache OpenOffice 4.1.16 RCE mitigation until a patch is available.
*   **User Awareness Training**: Educate users about the risks of opening untrusted documents, even if they don't trigger macro warnings. Emphasize that files from unknown sources should never be opened, regardless of file type.
*   **Network Monitoring**: Implement network monitoring solutions to detect unusual outbound connections from office applications, which could indicate attempts to download malicious ODB or JAR files.
*   **[Endpoint](/glossary#endpoint) Protection**: Ensure endpoint detection and response ([EDR](/glossary#edr)) solutions are up-to-date and configured to detect and block suspicious process execution originating from office applications.

These vulnerabilities highlight the sophisticated ways attackers can chain seemingly innocuous features to achieve powerful execution capabilities, underscoring the ongoing need for vigilance and timely patching.

**Related:** [CVE-2026-32475: Elementor Pro Unauthenticated RCE Flaw](/blog/cve-2026-32475-elementor-pro-unauthenticated-rce-flaw), [CVE-2026-53413: Zoom Zero-Click RCE – Patch Now](/blog/cve-2026-53413-zoom-zero-click-rce-patch-now)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/libreoffice-openoffice-rce-via-malicious-spreadsheets
