Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions content/security/bulletin.html
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,12 @@ <h2>Apache OpenOffice Security Team Bulletin</h2>
subscribe to our <a href="alerts.html">security-alerts mailing list</a>.</strong>
</p>

<h3>Disclosed in Apache OpenOffice 4.1.16</h3>

<ul>
<li><a href="cves/CVE-2026-59265.html">CVE-2026-59265</a>: Opening a malicious document can lead to system takeover.</li>
</ul>

<h3>Fixed in Apache OpenOffice 4.1.16</h3>

<ul>
Expand Down
43 changes: 43 additions & 0 deletions content/security/cves/CVE-2026-59265.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
type=cve
cve=CVE-2026-59265
cvedesc=Opening a malicious document can lead to system takeover
tags=weekly links, java
status=published
~~~~~~

**Description**

A code execution issue in the Java integration in Apache OpenOffice allows a crafted untrusted document to trigger the execution of arbitrary, even remote, code when it is opened by the user.

This issue affects Apache OpenOffice: through 4.1.16.

This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Once 4.1.17 is released, users are recommended to upgrade to that version, which fixes the issue.

The LibreOffice suite reported this issue as CVE-2026-63277.

**Severity: Critical**

Thanks to the reporters for discovering this issue.

**Vendor: The Apache Software Foundation**

**Versions Affected**

All Apache OpenOffice versions 4.1.16 and older are affected.
OpenOffice.org versions may also be affected.

**Mitigation**

Until 4.1.17 is released, users can mitigate this issue by disabling the Java runtime integration: choose *Tools - Options - OpenOffice - Java* (*OpenOffice - Preferences - OpenOffice - Java* on macOS) and untick *Use a Java runtime environment*. This prevents the attack. If this is not possible, or as an extra precaution, avoid opening untrusted files entirely.

Once released, install Apache OpenOffice 4.1.17 for the latest maintenance and cumulative security fixes. Use the Apache OpenOffice [download page](https://www.openoffice.org/download/).

**Acknowledgements**

The Apache OpenOffice Security Team would like to thank Rick de Jager of the V12 security team, and Thomas Rinsma and Edoardo Geraci of Codean Labs, who independently discovered and reported this issue.

**Further Information**

For additional information and assistance, consult the [Apache OpenOffice Community Forums](https://forum.openoffice.org/) or make requests to the users@openoffice.apache.org public mailing list.

The latest information on Apache OpenOffice security bulletins can be found at the [Bulletin Archive](https://www.openoffice.org/security/bulletin.html) page.
Loading