A newly disclosed flaw in LibreOffice and Apache OpenOffice lets a booby-trapped spreadsheet run an attacker's code the moment it's opened — with none of the trust prompts that normally guard against malicious macros.
What happened
Researchers found that Calc's "database range" feature, which lets a spreadsheet pull in data from an external database and refresh it automatically, can be abused to load and execute arbitrary Java code. The external source is defined in an ODB file that names a JDBC driver, and that driver can point to a JAR file hosted anywhere — including an attacker-controlled server. When the spreadsheet opens and the range refreshes, the program fetches the JAR and runs it. No macro-style "do you trust this document?" warning is ever shown.
The attack only works when the application's Java support is switched on, and in the published proof of concept the payload simply launches the Calculator app as a harmless stand-in. Researchers note the same mechanism could run any Java code an attacker chooses, and the technique was verified on both Windows and Linux. There are no reports of it being used in real attacks so far.
Two independent research teams reported the issue — one to LibreOffice, another working with Apache on the OpenOffice side — with a public proof of concept covering both products.
LibreOffice has already shipped a fix (tracked as CVE-2026-63277) in its October 5 updates; versions 26.2.5, 26.8.0, and later are no longer affected. Apache OpenOffice has not yet patched its version of the bug (CVE-2026-59265) — every release through the current 4.1.16 is vulnerable, with a fix slated for 4.1.17.
Why it matters
Macro security has been a well-known battleground for office-document attacks for years, which is exactly why most users have learned to distrust "enable macros" prompts. This flaw sidesteps that defense entirely: a spreadsheet can reach full code execution through a feature most users have never heard of, with zero warning dialog. Any organization that routinely opens spreadsheets from outside senders — vendors, job applicants, finance partners — is exposed until it's patched or mitigated.
What to do
- Update LibreOffice to 26.2.5 / 26.8.0 or later immediately.
- Apache OpenOffice users should disable Java support in the application's settings (Tools > Options > Advanced) until 4.1.17 ships, or avoid opening spreadsheets from untrusted sources in the meantime.
- Treat unsolicited spreadsheet attachments with the same caution as macro-enabled documents, regardless of whether a warning appears.
- Security teams should flag outbound connections initiated by office applications to unfamiliar hosts — a real attack would fetch its payload from a remote server, not a local file.
