← Back to CVE List
CVE-2026-63267NVD
Vulnerability Summary
LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. In fixed versions external data links are updated under the same link update control as other links in a spreadsheet.
CVSS v4.0 Base Metrics — Score 6.7 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionPassive
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)None
Availability (Vulnerable System)None
Confidentiality (Subsequent System)High
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- The Document Foundation LibreOffice >= 26.2 and < < 26.2.5
- The Document Foundation LibreOffice < 26.2.5