CVE-2023-6186: Debian Linux

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

Affected products

  • Debian Debian Linux: version 11.0 only; version 12.0 only
  • Fedoraproject Fedora: version 38 only
  • Libreoffice Libreoffice: from 7.5.0, before 7.5.9 (fixed in 7.5.9); from 7.6.0, before 7.6.4 (fixed in 7.6.4)

Published 2023-12-11. Last modified 2026-06-17.