Security researchers have demonstrated that opening a crafted spreadsheet in LibreOffice or Apache OpenOffice can execute arbitrary code without the usual macro warning. The attack relies on the spreadsheet's database range feature, which automatically refreshes data from an external source. By pointing that source to a malicious ODB file, the program downloads a Java database driver (JDBC) from a remote server and runs it inside the application. Each component is a legitimate feature, but combined they bypass the user consent normally required for macros.

The flaw affects both office suites when Java support is enabled. LibreOffice has released fixes (CVE-2026-63277) in versions 26.2.5 and 26.8.0, while Apache OpenOffice has not yet patched the corresponding issue (CVE-2026-59265); all versions up to 4.1.16 are vulnerable, with a fix expected in 4.1.17. The researchers tested the proof of concept on Windows and Linux and found it works on both.

There are no reports of the attack being used in the wild, and the proof of concept only launched the Calculator app as a harmless demonstration. Until Apache OpenOffice ships its fix, users can block the attack by disabling Java in the program's settings or by avoiding spreadsheets from untrusted sources. The vulnerabilities were reported by independent security teams, and the LibreOffice patch was contributed by Collabora Productivity.