CVE-2026-63266

unknown
Published 2026-10-05 · Modified 2026-10-05
CVSS v3
—
CVSS v4 NEW
6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
VIR risk
—

Description

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-63266 NameCVE-2026-63266 DescriptionArbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source…

CVE-2026-63266

NameCVE-2026-63266
DescriptionArbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libreoffice (PTS)bookworm4:7.4.7-1+deb12u14vulnerable
bookworm (security)4:7.4.7-1+deb12u13vulnerable
trixie4:25.2.3-2+deb13u6vulnerable
trixie (security)4:25.2.3-2+deb13u7vulnerable
forky4:26.8.0.3-2fixed
sid4:26.8.1.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libreofficesource(unstable)4:26.2.5.2-1

Notes

https://www.libreoffice.org/security/#cve-2026-63266

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://www.libreoffice.org/security/#cve-2026-63266

OS impact

debian Debian Mixed 4 releases
VersionStatusFixed in
trixie Affected —
sid Fixed 4:26.2.5.2-1
forky Fixed 4:26.2.5.2-1
bookworm Affected —

References

CWEs

CWE-22

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.