Malicious Spreadsheets Can Run Code Without Macro Warnings in LibreOffice, OpenOffice

LibreOffice has patched a spreadsheet code execution flaw, while Apache OpenOffice remains vulnerable to attacks that bypass macro security warnings.

Oct 7, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

LibreOffice has patched a Java code execution vulnerability, while Apache OpenOffice remains exposed as researchers demonstrate how malicious spreadsheets can bypass macro security warnings.

Malicious spreadsheets can execute Java code in LibreOffice Calc and Apache OpenOffice Calc without displaying the usual macro security warnings.

The vulnerabilities, tracked as CVE-2026-63277 and CVE-2026-59265, allow attacker-controlled code to run when users open specially crafted documents with Java integration enabled. LibreOffice has released fixes, but Apache OpenOffice remains vulnerable through version 4.1.16.

Researchers have demonstrated the technique publicly, although exploitation in the wild has not been confirmed. The attack exploits spreadsheet database connections rather than requiring users to approve macro execution.

How malicious spreadsheets execute Java code

In an October 5 security advisory, The Document Foundation disclosed that LibreOffice Calc could load Java database drivers from remote locations through external spreadsheet data connections.

A crafted spreadsheet can reference a remote OpenDocument Database (ODB) file configured to load a Java Database Connectivity (JDBC) driver from an attacker-controlled Java archive. Opening the document can trigger Java code execution without displaying a macro security prompt.

Researchers Rick de Jager of V12 Security and Thomas Rinsma and Edoardo Geraci of Codean Labs independently reported the vulnerability. A public proof of concept demonstrated code execution using a calculator application as a harmless payload.

The attack requires Java integration to be enabled. Thailand's Computer Emergency Response Team also documented the vulnerability on October 7, reporting successful proof-of-concept testing on Windows and Linux.

The exposure adds to concerns about untrusted files reaching vulnerable software. Recent incidents involving phishing lures disguised as business documents and a malicious HEIF upload targeting file-processing software involved different attack methods but similarly highlighted risks from untrusted content.

Advertisement

LibreOffice patched; OpenOffice fix still pending

LibreOffice fixed CVE-2026-63277 in versions 26.2.5 and 26.8.0. The update restricts Java classpath entries to file URLs, blocking the remote driver-loading mechanism.

Apache OpenOffice's security advisory rates CVE-2026-59265 critical and identifies versions 4.1.16 and earlier as affected. Version 4.1.17 remained in the release candidate phase as of October 8, 2026.

Apache recommends disabling Java integration through Tools > Options > OpenOffice > Java and deselecting Use a Java runtime environment. Organizations unable to disable Java should avoid opening untrusted documents.

Publicly released exploits for separate WordPress remote code execution vulnerabilities further illustrate the importance of addressing disclosed security flaws before attackers can exploit them.

Organizations should also implement these safeguards:

  • Patch affected applications: Deploy fixed LibreOffice versions, verify installations and track OpenOffice 4.1.17.
  • Disable unnecessary Java functionality: Turn off Java integration and remove unused runtimes where business requirements permit.
  • Restrict untrusted documents and network access: Filter suspicious attachments, isolate external spreadsheets and limit outbound connections.
  • Enforce least-privilege access: Restrict permissions, apply application allowlisting where supported and isolate automated document-processing workloads.
  • Monitor suspicious activity: Investigate unexpected Java execution and outbound network connections associated with office applications.
  • Test incident response plans: Exercise endpoint isolation, evidence preservation and recovery procedures for document-based attacks.

Until Apache releases its fix, disabling Java integration remains the most direct protection against this attack path. Additional safeguards can limit exposure but do not replace patching.

Read more: A separate ClickFix campaign involving malicious ChatGPT GPTs shows how attackers can also trick users into executing malware without exploiting a software vulnerability.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.