CVE-2026-63266: The Document Foundation Libreoffice
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Affected products
- The Document Foundation Libreoffice: from 26.2, before 26.2.5 (fixed in 26.2.5)
Published 2026-10-05. Last modified 2026-10-06.