Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

The Hacker News by The Hacker News
October 6, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalOct 06, 2026Vulnerability / Open Source

A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker’s code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.

The attack works only when the program’s Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.

LibreOffice has already fixed the flaw, which it tracks as CVE-2026-63277, in updates released on October 5. It recommends that users move to version 26.2.5 or 26.8.0. Versions before those are affected.

Apache OpenOffice has not fixed the matching flaw, which it tracks as CVE-2026-59265. Every version up to and including its current release, 4.1.16, is affected, and the project says a fix is expected in version 4.1.17, which is still being tested.

Until then, Apache OpenOffice users can block the attack by turning off Java in the program’s settings, or by not opening spreadsheets they do not trust.

The attack combines features that each work as intended on their own. A LibreOffice or Apache OpenOffice Calc spreadsheet can hold a “database range”, a block of cells that pulls in data from an outside source and refreshes it by itself. That outside source can be a separate database file, called an ODB, named by a web address written into the spreadsheet.

When the spreadsheet is opened, the range refreshes and the program downloads the ODB from that web address. The ODB can name a Java database driver, known as a JDBC driver, and point to where the driver’s code lives, which can be a JAR file, a bundle of Java code, or on a remote server. The program then downloads the JAR and starts the driver, which is the attacker’s code, inside the program itself.

Each of these is a normal feature. The security problem, the researchers say, is that together they reach code execution without ever asking the user to trust the document, the way the program asks before it runs a macro.

In the proof of concept, the driver simply opens the Calculator app, a harmless stand-in, but the same path can run any Java code the attacker chooses. The researchers tested the attack on Windows and Linux and say it is not tied to one operating system.

In their demonstration, the malicious files sat on the same machine for convenience. The researchers say a real attack would instead place the database file and the code on an attacker-controlled server.

The flaw in LibreOffice was reported independently by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. Apache credits Codean Labs for the matching flaw in OpenOffice. The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.

The Hacker News has contacted The Document Foundation, which develops LibreOffice, and the Apache OpenOffice project for comment.



Source link

The Hacker News

The Hacker News

Next Post

SKYBOXE Enters Reseller Partnership to Offer Verizon Business Data Plans to Business Customers

Recommended.

Vero Fiber Breaks Ground on Corsicana’s First Fiber-to-the-Home Network

Vero Fiber Breaks Ground on Corsicana’s First Fiber-to-the-Home Network

February 25, 2025
Fed minutes show officials were in tight split over December rate cut

Fed minutes show officials were in tight split over December rate cut

December 30, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio