CVE-2026-63266

EUVD-2026-92417
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
libreoffice
bookworm
vulnerable
bookworm (security)
vulnerable
forky
4:26.8.0.3-2
fixed
sid
4:26.8.1.1-3
fixed
trixie
vulnerable
trixie (security)
4:25.2.3-2+deb13u8
fixed