MajorCritical vulnerability
CVE-2026-63277 (CVSS 8.5)
NVD · officialPublished Oct 5, 2026Risk 37/100
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
Technical details
CVSS
8.5
AV:LocalAC:LowPR:NoneUI:Passive
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source