
Researchers have shown that a malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as the file is opened, without the warning either program shows before it runs a macro. The attack works only when the program’s Java support is enabled. So far it has only been demonstrated as a proof of concept, and there are no reports of it being used in real attacks.
The attack chains together features that each work as designed. A Calc spreadsheet can hold a “database range” that pulls in outside data and refreshes itself on open, and that data source can be a database (ODB) file fetched from a web address written into the spreadsheet. The ODB can name a Java database driver and say where its code lives, such as a JAR file on a remote server. The program downloads and starts that driver, which is the attacker’s code, inside the program itself. In the public proof of concept the driver just opens the Calculator app, but the same path can run any Java code, and the researchers tested it on Windows and Linux. LibreOffice tracks its flaw as CVE-2026-63277 and fixed it in updates released October 5. Apache OpenOffice tracks its matching flaw as CVE-2026-59265 and has not shipped a fix yet.
How to check if you’re affected
Affected versions of LibreOffice are those before 26.2.5 and 26.8.0, the fixed releases LibreOffice recommends moving to. In Apache OpenOffice, every version up to and including the current 4.1.16 is affected, with a fix expected in 4.1.17, which is still being tested. Check your version under Help > About in either program.
Because the attack needs Java support, OpenOffice users who cannot wait can turn Java off in the program’s settings, and should avoid opening spreadsheets from sources they do not trust until 4.1.17 is released.
