← Back to CVE List
CVE-2026-63277NVD
Vulnerability Summary
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
CVSS v4.0 Base Metrics — Score 8.5 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- The Document Foundation LibreOffice >= 26.2 and < < 26.2.5
- The Document Foundation LibreOffice < 26.2.5