CVEFinder.io

CVE-2026-63277

๐Ÿ”ถ medium
๐Ÿ” Scan for this CVE
Summary

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.

CVSS Score
-
EPSS Score
0.2
Exploit Probability
Published Date
2026-10-05
First Seen: 2026-10-08
๐ŸŽฏ CISA SSVC Assessment Updated: Oct 5, 2026
๐Ÿ” Exploitation Status
None
No known exploits
โš™๏ธ Automatable
NO
Requires human interaction
๐Ÿ’ฅ Technical Impact
Total
Complete system compromise possible
๐Ÿ† Discovered By
Rick de Jager of the V12 security team (reporter) Thomas Rinsma and Edoardo Geraci from Codean Labs (reporter) Caolรกn McNamara of Collabora Productivity (remediation developer)
SSVC data provided by CISA
Last Modified 2026-10-06
CVSS Vector 4.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

๐Ÿ“ฆ Affected Products 0

No affected products information available

๐Ÿ”— References 1