Security researchers have identified vulnerabilities in LibreOffice and Apache OpenOffice that could allow malicious spreadsheets to execute attacker controlled code without displaying the usual warnings associated with macro execution. The issue affects spreadsheet files created for both office suites and relies on specific features being combined in a way that can bypass normal user trust prompts. Researchers have demonstrated the technique as a proof of concept, but there are currently no reports confirming that the vulnerability has been used in real world attacks. The attack requires Java support to be enabled within the affected applications.
LibreOffice has addressed the vulnerability through security updates released on October 5, tracking the issue as CVE-2026-63277. The organization has advised users to upgrade to LibreOffice versions 26.2.5 or 26.8.0, as versions released before these updates are affected. Apache OpenOffice has identified a similar vulnerability tracked as CVE-2026-59265, which remains unresolved in current versions, including version 4.1.16. The project has indicated that a fix is expected in version 4.1.17, which is currently undergoing testing. Until the update becomes available, Apache OpenOffice users can reduce risk by disabling Java functionality through application settings or avoiding spreadsheet files received from untrusted sources.
The attack method takes advantage of multiple legitimate features within LibreOffice and Apache OpenOffice. Researchers explained that Calc spreadsheets can contain database ranges, which are sections of cells designed to retrieve and refresh information from external data sources. These external sources can include database files known as ODB files, which can be referenced through web addresses embedded within a spreadsheet. When a user opens a specially crafted spreadsheet, the database range can automatically attempt to refresh data by downloading the referenced ODB file. The downloaded file can specify a Java database connectivity driver, commonly known as a JDBC driver, along with a location containing Java code. This can result in the application downloading and loading a Java archive file containing code controlled by an attacker.
According to researchers, each individual feature involved in the process operates as intended, but their combination creates a security concern because it may lead to code execution without requiring the user to approve document trust in the same way required for macros. In their proof of concept demonstration, researchers used a harmless example that launched the Calculator application, showing that the execution path could be triggered without causing damage. However, they noted that the same method could potentially allow other Java based actions depending on the code included by an attacker. Testing was conducted on both Windows and Linux systems, indicating that the technique is not limited to a single operating system environment.
Researchers from V12 security team and Codean Labs were involved in identifying the vulnerabilities. The V12 team published proof of concept material demonstrating the issues in both applications, while Apache OpenOffice credited Codean Labs for reporting the related vulnerability. The LibreOffice fix was developed by Caolán McNamara of Collabora Productivity. Security researchers have recommended that users apply available updates, review Java settings within affected office applications, and exercise caution when opening spreadsheet files from unknown sources. As office productivity tools remain widely used across personal and business environments, timely patching and secure document handling practices continue to be important measures for reducing exposure to software vulnerabilities.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.