CVE-2026-59265: Apache OpenOffice: Opening a malicious document can lead to system takeover
Opening a crafted document in Apache OpenOffice 4.1.16 and earlier can execute arbitrary code and take over the system.
Dave Fisher disclosed CVE-2026-59265, a critical code-execution flaw in Apache OpenOffice through version 4.1.16. A bug in the Java integration lets a crafted untrusted document execute arbitrary code, including remote code, when a user opens it, which can lead to system takeover. Affected builds also include those before commits 95923fd437e06edd38a4f0e139a27c755a6f3ba6 and 181421139242694b309751fb666406eddc203c50. The notice does not report exploitation in the wild.
- Affects Apache OpenOffice through 4.1.16.
- Java integration lets a crafted document execute arbitrary code when opened.
- Code may be remote, enabling system takeover after user interaction.
- Fixes are tied to two published commits; exploitation is not reported.
Vulnerabilities mentionedAll →
- CVE-2026-592658.8<1%Code execution via Java integration in Apache OpenOfficepublished · Apache Software Foundation Apache OpenOffice PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-59265 | Code execution via Java integration in Apache OpenOffice |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha1 | 181421139242694b309751fb666406eddc203c50 | 37e06edd38a4f0e139a27c755a6f3ba6 - Apache OpenOffice before 181421139242694b309751fb666406eddc203c50 Description: A code execution issue in the Java integration |
| sha1 | 95923fd437e06edd38a4f0e139a27c755a6f3ba6 | Apache OpenOffice through 4.1.16 - Apache OpenOffice before 95923fd437e06edd38a4f0e139a27c755a6f3ba6 - Apache OpenOffice before 181421139242694b309751fb666406ed |
Posted by Dave Fisher on Oct 02 Severity: critical Affected versions: - Apache OpenOffice through 4.1.16 - Apache OpenOffice before 95923fd437e06edd38a4f0e139a27c755a6f3ba6 - Apache OpenOffice before 181421139242694b309751fb666406eddc203c50 Description: A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected...
This source does not provide full text. Read it at seclists.org.