Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63268— LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href

Quick assessment

Affected
The Document Foundation LibreOffice
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LibreOffice Calc 允许将单元格区域链接到外部数据源,并且该链接会保存在文档中。对于 SQL 类型的链接,可以指定一个本地文本文件文件夹作为数据库,因此打开文档时可能会将本地文本文件读入工作表中。在修复版本中,仅在加载文档时恢复 CSV、HTML 和 XML 数据提供者。

CVSS 6.7 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63268

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href
Source: CVE Program / CVE List V5
Vulnerability Description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A link of the sql type could name a folder of local text files as a database, so opening a document could read a local text file into the sheet. In fixed versions only the csv, html and xml data providers are restored when a document is loaded.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
The Document Foundation LibreOffice 26.2 ~ < 26.2.5 -

II. Public POCs for CVE-2026-63268

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63268

请登录查看更多情报信息。

Other References for CVE-2026-63268 (1)

Same Patch Batch · The Document Foundation · 2026-10-05 · 6 CVEs total

CVE-2026-63277 8.5 HIGH RCE via calcext:data-mappings, sql provider and jdbc connector
CVE-2026-63266 6.8 MEDIUM Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functiona
CVE-2026-63270 6.7 MEDIUM Environment/ini-file leaks
CVE-2026-63269 6.7 MEDIUM LFI and GET SSRF via GStreamer and HLS playlists
CVE-2026-63267 6.7 MEDIUM LFI and GET SSRF via calcext:data-mappings and csv provider

IV. Related Vulnerabilities

V. Comments for CVE-2026-63268

No comments yet


Leave a comment