PatchSiren cyber security CVE debrief
CVE-2026-63267 The Document Foundation CVE debrief
LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document. Such a link was fetched while the document loaded, so opening a document could read a local file into the sheet, or make a request to a host of the document's choosing. The vulnerability requires verification of LibreOffice installations and external data link usage to prevent potential exploitation. Defenders should assess exposure and prioritize updates, particularly in environments where Calc is used to access external data sources.
- Vendor
- The Document Foundation
- Product
- LibreOffice
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for managing LibreOffice installations, particularly in environments where Calc is used to access external data sources, should assess exposure and prioritize updates.
Why it matters
Defenders should care about CVE-2026-63267 because it allows for potential data exposure or unauthorized requests when opening a LibreOffice Calc document with an external csv data link. This vulnerability requires verification of LibreOffice installations and external data link usage to prevent potential exploitation.
- Potential data exposure through reading local files
- Potential unauthorized requests to external hosts
- Verification of LibreOffice version and external data link usage
- Prioritization of updates to prevent potential exploitation
Technical summary
The vulnerability allows an attacker to potentially read a local file into the sheet or make a request to a host of the document's choosing when a document with an external csv data link is opened. This requires defenders to assess exposure and prioritize updates, particularly in environments where Calc is used to access external data sources. The vulnerability has been addressed in fixed versions of LibreOffice, where external data links are updated under the same link update control as other links in a spreadsheet.
Defensive priority
Defenders should prioritize verifying and updating LibreOffice installations to prevent potential data exposure or unauthorized requests.
Recommended defensive actions
- Verify and update LibreOffice installations to the latest version
- Review and restrict external data links in Calc documents
- Monitor for suspicious activity or potential data exposure
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Additional details may be available from the LibreOffice security advisory. Defenders should verify LibreOffice installations and external data link usage to prevent potential exploitation. The vulnerability allows an attacker to potentially read a local file into the sheet or make a request to a host of the document's choosing when a document with an external csv data link is opened. There is no information on known or unknown affected scope.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-63267 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-63267
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-63267 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-63267
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.libreoffice.org/about-us/security/advisories/cve-2026-63267
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.