CVE-2026-63277
๐ถ mediumSummary
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
CVSS Score
-
EPSS Score
0.2
Exploit Probability
Published Date
2026-10-05
First Seen: 2026-10-08
๐ฏ CISA SSVC Assessment Updated: Oct 5, 2026
๐ Exploitation Status
None
No known exploits
โ๏ธ Automatable
NO
Requires human interaction
๐ฅ Technical Impact
Total
Complete system compromise possible
๐ Discovered By
Rick de Jager of the V12 security team (reporter)
Thomas Rinsma and Edoardo Geraci from Codean Labs (reporter)
Caolรกn McNamara of Collabora Productivity (remediation developer)
SSVC data provided by
CISA
Last Modified
2026-10-06
Source
NVD ๐
CVSS Vector 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)