{"id":"CVE-2026-63266","title":"LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document","summary":"LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. …","severity":"medium","cvss":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-22"],"vendor":"The Document Foundation","product":"LibreOffice","affected":["LibreOffice >= 26.2 < < 26.2.5"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T13:16:53.510","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63266","references":[{"url":"https://www.libreoffice.org/about-us/security/advisories/cve-2026-63266","label":"security@documentfoundation.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-05T12:42:40.333248Z"},"cvssSource":"cna","ingestedAt":"2026-10-05T12:19:22.671Z","slug":"CVE-2026-63266","body":"## Overview\n\nLibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}