CVE-2026-63270Medium· 6.7▾ SunlitURLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not cover every place a document can supply a URL. XForms instance data and the Calc csv and sql data providers still reached the expansion. In fixed versions these places refuse URLs with internal schemes when the URL comes from the document.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63269Medium· 6.7LibreOffice can link to audio and video files from a document, and on Linux it plays them with GStreamer
CVE-2026-63267Medium· 6.7LibreOffice Calc can link a cell range to an external csv data source, and the link is saved in the document
CVE-2026-63268Medium· 6.7LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document
CVE-2026-63278Medium· 6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links
CVE-2026-63277High· 8.5LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document
CVE-2026-63266Medium· 6.8LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document