A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.
The attack works only when the program’s Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.
LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected.
Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265. Every version up to and including its current release, 4.1.16, is affected, and the project says a fix is expected in version 4.1.17, which is still being tested.
Until then, Apache OpenOffice users can block the attack by turning off Java in the program’s settings, or by not opening spreadsheets they do not trust.
The attack combines features that each work as intended on their own. A LibreOffice or Apache OpenOffice Calc spreadsheet can hold a “database range”, a block of cells that pulls in data from an outside source and refreshes it by itself. That outside source can be a separate database file, called an ODB, named by a web address written into the spreadsheet.
When the spreadsheet is opened, the range refreshes and the program downloads the ODB from that web address. The ODB can name a Java database driver, known as a JDBC driver, and point to where the driver’s code lives, which can be a JAR file, a bundle of Java code, or on a remote server. The program then downloads the JAR and starts the driver, which is the attacker’s code, inside the program itself.
Each of these is a normal feature. The security problem, the researchers say, is that together they reach code execution without ever asking the user to trust the document, the way the program asks before it runs a macro.
In the proof of concept, the driver simply opens the Calculator app, a harmless stand-in, but the same path can run any Java code the attacker chooses. The researchers tested the attack on Windows and Linux and say it is not tied to one operating system.
In their demonstration, the malicious files sat on the same machine for convenience. The researchers say a real attack would instead place the database file and the code on an attacker-controlled server.
The flaw in LibreOffice was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. Apache credits Codean Labs for the matching flaw in OpenOffice. The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.
The Hacker News has contacted The Document Foundation, which develops LibreOffice, and the Apache OpenOffice project for comment.
📰 Original Source:TheHackerNews ✍️ Author: info@thehackernews.com (The Hacker News)
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Leave a Reply