Skip to content

CVE lookup

CVE-2026-63266

Pruva has a verified reproduction for CVE-2026-63266: Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality — document-driven write to any user-writable path. The canonical evidence record is REPRO-2026-00376.

REPRO

REPRO-2026-00376

Package

LibreOffice/core · other

Severity

HIGH

Status

published