
CVE-2026-63277: LibreOffice Calc RCE via calcext:data-mappings, sql provider and jdbc connector — document-named Java DB driver loaded from a remote class path URL on open https://www.pruva.dev/reproductions/REPRO-2026-00374
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

CVE-2026-63277: LibreOffice Calc RCE via calcext:data-mappings, sql provider and jdbc connector — document-named Java DB driver loaded from a remote class path URL on open https://www.pruva.dev/reproductions/REPRO-2026-00374

Someone can email you a LibreOffice spreadsheet that runs their code on your computer the moment you open it. Fixed today in 26.2.5 (CVE-2026-63277), plus five bugs that let a file read or write files on your machine. Update before the next attachment. https://hol.org/blog/cve-2026-63277-libreoffice-calc-external-data-jdbc-rce https://t.co/pKkv7b8s4P

🔴 V12 Security, LibreOffice Calc'taki RCE açığı CVE-2026-63277 için PoC yayınladı. Zararlı bir .ods dosyasının açılmasıyla, uzak JDBC sürücüsü üzerinden Java kodu çalıştırılabiliyor. CVSS: 8.5 High ✅ Düzeltilen sürümler: 26.2.5 / 26.8.0 👉 OpenOffice de benzer bir güvenlik açığından etkileniyor: CVE-2026-59265. Mutlaka yazılım sürümlerini güncelleyin. https://x.com/v12sec/status/2107142692853469503/video/1 PoC: https://github.com/v12-security/pocs/tree/main/office_jdbc_bugs

A PoC/exploit has been discovered for vulnerability CVE-2026-63277 PT ID: PT-2026-104818 Read on dbugs: https://dbu.gs/vulnerability/PT-2026-104818 Vendor: The Document Foundation Product: LibreOffice Description: LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL. Link: https://github.com/v12-security/pocs/tree/main/office_jdbc_bugs

PoC released for LibreOffice Calc vulnerability CVE-2026-63277, which runs code when a file opens. Five more flaws fixed. Upgrade to 26.2.5. #LibreOffice #LibreOfficeCalc #CVE202663277 #CVE202663266 #PoC #RCE #OpenSource #Vulnerability https://securityonline.info/libreoffice-calc-vulnerability-cve-2026-63277-poc/
LibreOffice Calc Vulnerability CVE-2026-63277: PoC Out - https://securityonline.info/libreoffice-calc-vulnerability-cve-2026-63277-poc/

LibreOfficeに表計算ファイルを開くだけでコードが実行される脆弱性、修正版26.2.5と26.8.0を公開 — CVE-2026-63277など6件に対処 https://cyber.nexsight.co/articles/2026/10/06/libreoffice-calc-rce-cve-2026-63277-26-2-5-2026-10-06/

A LibreOffice spreadsheet could name a remote Java driver and run its code on open. The Calc data links behind four of six new CVEs were never under the link-update prompt. No exploitation reported. https://severitydaily.com/libreoffice-cve-2026-63277-calcext-data-mappings-link-update-bypass-jdbc-rce/