CVE-2026-63266

Published: October 6, 2026Last modified: October 7, 2026

Description

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibreoffice-headlessVulnerable (7.6.3.2-r3)
25 LTSlibreoffice-headlessVulnerable (25.2.3.2-r0)
Streamlibreoffice-headlessVulnerable (7.6.4.1-r1)

References

ON THIS PAGE