
LibreOffice and OpenOffice Spreadsheet Flaws Allow Silent Code Ex
Malicious spreadsheets can run hidden code in LibreOffice and Apache OpenOffice without a macro warning. LibreOffice is fixed; OpenOffice users should disable J…
A security flaw in two widely used office suites allows a malicious spreadsheet to run an attacker's code as soon as the file is opened, without showing the type of macro warning (a prompt before a small embedded program runs) that normally appears before code runs. Researchers demonstrated that LibreOffice and Apache OpenOffice can both be affected when their Java support, an optional component used for some advanced features, is enabled. The finding has so far been shown only as a proof of concept, and there are no reports of the technique being used in real attacks.
LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. The project recommends that users move to version 26.2.5 or 26.8.0; earlier versions remain affected. Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265. Every version up to and including the current release, 4.1.16, is affected, and the project says a fix is expected in version 4.1.17, which is still being tested. Until that version arrives, OpenOffice users can block the attack by turning off Java in the program's settings or by not opening spreadsheets they do not trust.
The technique begins with a normal spreadsheet feature called a database range. In a LibreOffice or Apache OpenOffice Calc spreadsheet, a database range is a block of cells that pulls in data from an outside source and refreshes itself automatically. The outside source can be a separate database file, called an ODB, named by a web address written into the spreadsheet. When the spreadsheet is opened, the range refreshes and the program downloads the ODB from that web address. This first step happens without any prompt or warning to the user.
The downloaded ODB can then name a Java database driver, known as a JDBC driver, which is a piece of software that lets the program communicate with an external database. The ODB can point to where the driver's code lives, which can be a JAR file (a packaged collection of Java code) or a location on a remote server. The program then downloads the JAR and starts the driver, which is the attacker's code, inside the program itself. Each step is a normal feature of the office suite. The security problem, researchers say, is that together they reach code execution without ever asking the user to trust the document, the way the program asks before it runs a macro.
In the proof of concept, the driver simply opens the Calculator app, a harmless stand-in, but the same path can run any Java code the attacker chooses. The researchers tested the attack on Windows and Linux and say it is not tied to one operating system. In their demonstration, the malicious files sat on the same machine for convenience; a real attack would instead place the database file and the code on an attacker-controlled server. The flaw in LibreOffice was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. Apache credits Codean Labs for the matching flaw in OpenOffice. The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.
The Hacker News has contacted The Document Foundation, which develops LibreOffice, and the Apache OpenOffice project for comment. For website owners, businesses and IT teams, the finding is a reminder that document-based attacks can sidestep warnings users have learned to expect. Keeping office suites patched and disabling optional components such as Java when they are not needed are simple ways to reduce the risk. Until users take those steps, simply opening an untrusted spreadsheet can be enough to hand control of the computer to an attacker. For teams that manage many machines, AEU-I offers security-first IT, infrastructure and consulting that can support patch deployment and configuration reviews across an organisation.
How to Protect Yourself
- If you use LibreOffice, update it now to version 26.2.5 or 26.8.0 or later from the official site.
- If you use Apache OpenOffice, open the program's settings and turn off Java support until version 4.1.17 is released.
- Do not open spreadsheet files from emails, messages or websites unless you trust the sender and were expecting the file.
- If you receive an unexpected spreadsheet attachment, contact the sender through a different channel before opening it.
- Turn on automatic updates for your office software and operating system so future security fixes install quickly.
Vulnerabilities & Fixes
- CVE-2026-59265 Apache OpenOffice flaw affecting versions up to 4.1.16; fix expected in version 4.1.17, currently being tested. View the fix & details →
- CVE-2026-63277 LibreOffice flaw fixed in updates released on October 5; users should move to version 26.2.5 or 26.8.0. View the fix & details →
Terms Explained
- Java support An optional part of the office suite that lets it use extra features, including database connections; the attack only works when this is turned on.
- JDBC driver A piece of software that lets a program talk to an external database; a Java database driver.
- JAR file A single file that bundles many pieces of Java code together.
- ODB file A separate database file that a spreadsheet can download and use as an outside data source.
- database range A named block of cells in a spreadsheet that can pull in and refresh data from an outside source.
- macro A small program embedded in a document that normally asks for permission before running.
- Calc The spreadsheet application included in LibreOffice and Apache OpenOffice.