PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63266 The Document Foundation CVE debrief

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link, a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions, an embedded Firebird database can open or create files only inside its own private directory.

Vendor
The Document Foundation
Product
LibreOffice
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

LibreOffice users who open documents from untrusted sources or have write access to sensitive areas should assess exposure and prioritize remediation. This includes users with administrative privileges or access to sensitive data. Security teams and vulnerability management teams should verify LibreOffice versions and configurations, review compensating controls, and monitor for suspicious activity.

Why it matters

CVE-2026-63266 allows a LibreOffice Calc document to create files in sensitive areas through an embedded Firebird database. Defenders should assess exposure, prioritize remediation for high-risk users, and verify LibreOffice versions.

  • File creation in sensitive areas through embedded Firebird database.
  • Potential data integrity impact through unauthorized file modifications.
  • Increased risk for users who open documents from untrusted sources.
  • Verification of LibreOffice version and configuration required.

Technical summary

The vulnerability allows a document to open an embedded Firebird database that can write a file to any location the user can write to. Fixed versions restrict file creation to the embedded Firebird database's private directory. This issue affects LibreOffice Calc when linking a cell range to an external data source. The document could then open an embedded Firebird database, potentially writing files to sensitive areas based on user permissions. Technical analysis indicates that exploitation depends on user interaction with documents from untrusted sources.

Defensive priority

Assess exposure and prioritize remediation for LibreOffice users who open documents from untrusted sources or have write access to sensitive areas.

Recommended defensive actions

  • Assess exposure by identifying LibreOffice users who open documents from untrusted sources or have write access to sensitive areas.
  • Prioritize remediation for high-risk users, such as those with administrative privileges or access to sensitive data.
  • Verify that LibreOffice is updated to a fixed version that restricts embedded Firebird database file creation to its private directory.
  • Monitor for suspicious activity, such as unexpected file creations or modifications, in areas accessible to LibreOffice users.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. The LibreOffice security advisory provides additional information on the fixed versions. Through analysis and verification, defenders can confirm whether LibreOffice Calc documents from untrusted sources could open an embedded Firebird database that wrote files to sensitive locations. Evidence limits suggest verifying document sources and user access rights. The CVE Program and NVD entries offer source-provided metadata and vulnerability assessments. Additional review,

Sources and references

Verified primary and authoritative sources

  • CVE-2026-63266 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-63266

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-63266 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63266

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.