CVE-2026-63277 PUBLISHED

RCE via calcext:data-mappings, sql provider and jdbc connector

Assigner: Document Fdn.
Reserved: 16.07.2026 Published: 05.10.2026 Updated: 05.10.2026

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor The Document Foundation
Product LibreOffice
Versions Default: unknown
  • affected from 26.2 to < 26.2.5 (excl.)

Credits

  • Rick de Jager of the V12 security team reporter
  • Thomas Rinsma and Edoardo Geraci from Codean Labs reporter
  • Caolán McNamara of Collabora Productivity remediation developer

References

Problem Types

  • CWE-829 Inclusion of Functionality from Untrusted Control Sphere CWE

Impacts

  • CAPEC-175 Code Inclusion