CVE-2026-63266
Description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2026-63266 NameCVE-2026-63266 DescriptionArbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source…
CVE-2026-63266
| Name | CVE-2026-63266 |
| Description | Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| libreoffice (PTS) | bookworm | 4:7.4.7-1+deb12u14 | vulnerable |
| bookworm (security) | 4:7.4.7-1+deb12u13 | vulnerable | |
| trixie | 4:25.2.3-2+deb13u6 | vulnerable | |
| trixie (security) | 4:25.2.3-2+deb13u7 | vulnerable | |
| forky | 4:26.8.0.3-2 | fixed | |
| sid | 4:26.8.1.1-2 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| libreoffice | source | (unstable) | 4:26.2.5.2-1 |
Notes
https://www.libreoffice.org/security/#cve-2026-63266
Apply commands
https://www.libreoffice.org/security/#cve-2026-63266
OS impact
Debian Mixed 4 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Affected | — |
| sid | Fixed | 4:26.2.5.2-1 |
| forky | Fixed | 4:26.2.5.2-1 |
| bookworm | Affected | — |
References
CWEs
CWE-22
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.