CVE-2026-63266 PUBLISHED

Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality

Assigner: Document Fdn.
Reserved: 16.07.2026 Published: 05.10.2026 Updated: 05.10.2026

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor The Document Foundation
Product LibreOffice
Versions Default: unknown
  • affected from 26.2 to < 26.2.5 (excl.)

Credits

  • Thomas Rinsma and Edoardo Geraci from Codean Labs reporter
  • Caolán McNamara of Collabora Productivity remediation developer

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-597 Absolute Path Traversal