CVE-2026-63278Medium· 6.7▾ SunlitURLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise every way of naming the package content provider, so a URL that named it differently still reached the expansion. In fixed versions the package content provider is matched when the URL is checked.
LibreOffice >= 26.2 < < 26.2.5Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63272Medium· 5.4Heap buffer overflow in WMF text record import
CVE-2026-63275Medium· 5.4Stack buffer overflow in CFF font hint handling
CVE-2026-63276Medium· 5.4Stack buffer overflow in CFF to Type 1 font conversion
CVE-2026-63273Medium· 5.4Heap buffer overflow in PDF import encryption handling
CVE-2026-63274Medium· 5.4Heap buffer overflow in PDF import stream handling
CVE-2026-63279Medium· 5.4Out of bounds read in PICT image import