PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63267 The Document Foundation CVE debrief

LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. The vulnerability requires verification of LibreOffice installations and external data link usage to prevent potential exploitation. Defenders should assess exposure and prioritize updates, particularly in environments where Calc is used to access external data sources.

Vendor
The Document Foundation
Product
LibreOffice
CVSS
MEDIUM 6.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for managing LibreOffice installations, particularly in environments where Calc is used to access external data sources, should assess exposure and prioritize updates.

Why it matters

Defenders should care about CVE-2026-63267 because it allows for potential data exposure or unauthorized requests when opening a LibreOffice Calc document with an external csv data link. This vulnerability requires verification of LibreOffice installations and external data link usage to prevent potential exploitation.

  • Potential data exposure through reading local files
  • Potential unauthorized requests to external hosts
  • Verification of LibreOffice version and external data link usage
  • Prioritization of updates to prevent potential exploitation

Technical summary

The vulnerability allows an attacker to potentially read a local file into the sheet or make a request to a host of the document's choosing when a document with an external csv data link is opened. This requires defenders to assess exposure and prioritize updates, particularly in environments where Calc is used to access external data sources. The vulnerability has been addressed in fixed versions of LibreOffice, where external data links are updated under the same link update control as other links in a spreadsheet.

Defensive priority

Defenders should prioritize verifying and updating LibreOffice installations to prevent potential data exposure or unauthorized requests.

Recommended defensive actions

  • Verify and update LibreOffice installations to the latest version
  • Review and restrict external data links in Calc documents
  • Monitor for suspicious activity or potential data exposure
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Additional details may be available from the LibreOffice security advisory. Defenders should verify LibreOffice installations and external data link usage to prevent potential exploitation. The vulnerability allows an attacker to potentially read a local file into the sheet or make a request to a host of the document's choosing when a document with an external csv data link is opened. There is no information on known or unknown affected scope.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-63267 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-63267

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-63267 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63267

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.