CVE-2026-63266: The Document Foundation Libreoffice

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.

Affected products

Published 2026-10-05. Last modified 2026-10-06.