Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63277— RCE via calcext:data-mappings, sql provider and jdbc connector

Quick assessment

Affected
The Document Foundation LibreOffice
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LibreOffice Calc 可以将单元格范围链接到外部数据源,并且该链接会保存在文档中。文档可以为这样的链接指定一个 Java 数据库驱动程序,从而允许从远程位置加载该驱动程序,因此在打开文档时可能会执行来自该位置的 Java 代码。在修复版本中,Java 类路径中的条目必须是文件 URL。

CVSS 8.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63277

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RCE via calcext:data-mappings, sql provider and jdbc connector
Source: CVE Program / CVE List V5
Vulnerability Description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
从非可信控制范围包含功能例程
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
The Document Foundation LibreOffice 26.2 ~ < 26.2.5 -

II. Public POCs for CVE-2026-63277

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63277

请登录查看更多情报信息。

Other References for CVE-2026-63277 (1)

Same Patch Batch · The Document Foundation · 2026-10-05 · 6 CVEs total

CVE-2026-63266 6.8 MEDIUM Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functiona
CVE-2026-63270 6.7 MEDIUM Environment/ini-file leaks
CVE-2026-63269 6.7 MEDIUM LFI and GET SSRF via GStreamer and HLS playlists
CVE-2026-63267 6.7 MEDIUM LFI and GET SSRF via calcext:data-mappings and csv provider
CVE-2026-63268 6.7 MEDIUM LFI via calcext:data-mappings, sql provider and sdbc:flat:file:// db href

IV. Related Vulnerabilities

V. Comments for CVE-2026-63277

No comments yet


Leave a comment