This is an automated email from the ASF dual-hosted git repository. dave2wave pushed a commit to branch dave2wave-patch-2 in repository https://gitbox.apache.org/repos/asf/openoffice-org.git
commit 67c5e2dad5b6060adf83b390d7fac96119d91501 Author: Dave Fisher <[email protected]> AuthorDate: Fri Oct 2 10:12:37 2026 -0700 Bulletin --- content/security/cves/CVE-2026-59265.md | 43 +++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) diff --git a/content/security/cves/CVE-2026-59265.md b/content/security/cves/CVE-2026-59265.md new file mode 100644 index 0000000000..2bc31dbe55 --- /dev/null +++ b/content/security/cves/CVE-2026-59265.md @@ -0,0 +1,43 @@ +type=cve +cve=CVE-2026-59265 +cvedesc=Opening a malicious document can lead to system takeover +tags=weekly links, java +status=published +~~~~~~ + +**Description** + +A code execution issue in the Java integration in Apache OpenOffice allows a crafted untrusted document to trigger the execution of arbitrary, even remote, code when it is opened by the user. + +This issue affects Apache OpenOffice: through 4.1.16. + +This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Once 4.1.17 is released, users are recommended to upgrade to that version, which fixes the issue. + +The LibreOffice suite reported this issue as CVE-2026-63277. + +**Severity: Critical** + +Thanks to the reporters for discovering this issue. + +**Vendor: The Apache Software Foundation** + +**Versions Affected** + +All Apache OpenOffice versions 4.1.16 and older are affected. +OpenOffice.org versions may also be affected. + +**Mitigation** + +Until 4.1.17 is released, users can mitigate this issue by disabling the Java runtime integration: choose *Tools - Options - OpenOffice - Java* (*OpenOffice - Preferences - OpenOffice - Java* on macOS) and untick *Use a Java runtime environment*. This prevents the attack. If this is not possible, or as an extra precaution, avoid opening untrusted files entirely. + +Once released, install Apache OpenOffice 4.1.17 for the latest maintenance and cumulative security fixes. Use the Apache OpenOffice [download page](https://www.openoffice.org/download/). + +**Acknowledgements** + +The Apache OpenOffice Security Team would like to thank Rick de Jager of the V12 security team, and Thomas Rinsma and Edoardo Geraci of Codean Labs, who independently discovered and reported this issue. + +**Further Information** + +For additional information and assistance, consult the [Apache OpenOffice Community Forums](https://forum.openoffice.org/) or make requests to the [email protected] public mailing list. + +The latest information on Apache OpenOffice security bulletins can be found at the [Bulletin Archive](https://www.openoffice.org/security/bulletin.html) page.
