Skip to content

CVE-2026-63277: Verified Reproduction

CVE-2026-63277: LibreOffice Calc RCE via calcext:data-mappings, sql provider and jdbc connector — document-named Java DB driver loaded from a remote class path URL on open

CVE-2026-63277 is verified against the affected target. Vulnerability class: RCE. This high reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00374.

REPRO-2026-00374 RCE Oct 5, 2026 CVE entry .txt
Severity
HIGH
Confidence
HIGH
Reproduced in
144m 55s
Tool calls
604
Spend
$37.04
01 · Overview

What Is CVE-2026-63277?

CVE-2026-63277 is a high-severity RCE vulnerability. Pruva has independently reproduced it and publishes a verified, runnable proof-of-concept (reproduction REPRO-2026-00374).

02 · Severity & CVSS

CVE-2026-63277 Severity

CVE-2026-63277 is rated high severity.

HIGH threat level

High — serious impact or readily exploitable. Prioritize remediation.

How to Reproduce CVE-2026-63277

$ pruva-verify REPRO-2026-00374
or curl -O https://www.pruva.dev/api/v1/reproductions/REPRO-2026-00374/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh
Run in a VM or disposable container. This exploits a real vulnerability.
06 · Proof of Reproduction

Proof of Reproduction for CVE-2026-63277

Remote code execution — reproduced
  • reached the target end-to-end
  • full exploit chain demonstrated
  • on the real production code path
  • high confidence
  • the upstream fix blocks the same trigger
Trigger

Crafted .ods data mapping, remote .odb JDBC settings, Java driver class name, and HTTP Java class path

Attack chain
  1. LibreOffice Calc document open
  2. calcext:data-mapping
  3. SQLDataProvider
  4. remote ODB
  5. JDBC class loader
How the agent worked 1,075 events · 604 tool calls · 2h 25m
2h 25mDuration
604Tool calls
74Reasoning steps
1,075Events
23Dead-ends
Agent activity over 2h 25m
Policy
1
Support
19
Repro
597
Judge
30
Variant
423
Verify
1
0:00144:36

Root Cause and Exploit Chain for CVE-2026-63277

Versions: component: LibreOffice Calc external data mappings, SQL data provider, database document loader, JDBC connector, and jvmaccess::ClassPath.Fixed: control: Official LibreOffice 26.2.5.2 (build commit cd7284b4cbbfeb507e630c1aac019f4157393acb).

LibreOffice Calc 26.2.4.2 and earlier can automatically process a persisted calcext:data-mappings SQL data provider while opening an attacker-crafted .ods. The mapping's identifier can point to a remote .odb database document. That database document controls the JDBC driver class name and JavaDriverClassPath; vulnerable LibreOffice passes an HTTP class-path URL into its Java class loader without restricting it to local files. As a result, opening the spreadsheet causes Calc to retrieve and initialize an attacker-controlled Java class. This run demonstrated that behavior through the real soffice document-open path and recorded target-local code-execution markers.

  • Affected component: LibreOffice Calc external data mappings, SQL data provider, database document loader, JDBC connector, and jvmaccess::ClassPath.
  • Affected versions: Reproduced with official LibreOffice 26.2.4.2 (build commit 0229ac93fcf0d7cbc6376066c6f35021cef002dc). The vendor states the issue is fixed in 26.2.5 and 26.8.0.
  • Fixed control: Official LibreOffice 26.2.5.2 (build commit cd7284b4cbbfeb507e630c1aac019f4157393acb).
  • Risk: High. A malicious spreadsheet can execute Java bytecode with the privileges of the LibreOffice user when the document is opened. The executed Java code can access files, processes, and network resources available to that account.

Impact Parity

  • Disclosed/claimed maximum impact: Code execution from a crafted Calc document.
  • Reproduced impact: Attacker-controlled Java code execution in the real LibreOffice process path. The remote driver's static initializer wrote CVE-2026-63277_REMOTE_JDBC_CODE_EXECUTION to a unique marker for each vulnerable attempt.
  • Parity: full
  • Not demonstrated: No additional privilege escalation was attempted or claimed. The payload intentionally used a harmless file marker rather than launching a shell.

Root Cause

The ODS importer creates an ExternalDataSource for every persisted calcext:data-mapping. The vulnerable import path refreshes each mapping immediately when the mapping context is destroyed. For calcext:provider="org.libreoffice.calc.sql", SQLDataProvider parses an ID of the form <table>@<database> and gives <database> to com.sun.star.sdb.DatabaseContext::getByName. If the name is not registered, the database context treats it as a URL and loads the referenced .odb.

The remotely supplied .odb can persist:

  • db:connection-resource selecting a JDBC URL;
  • db:java-driver-class selecting an attacker-defined driver class; and
  • db:java-classpath selecting where that class is loaded from.

In vulnerable builds, jvmaccess::ClassPath::translateToUrls converts every class-path entry into a Java URL without constraining its scheme. Therefore an HTTP entry reaches a Java class loader, which downloads and initializes the selected JDBC driver. Java class initialization is already arbitrary code execution; it happens before a successful database query is necessary.

The fixed code adds URL parsing in jvmaccess/source/classpath.cxx and raises IllegalArgumentException unless every Java class-path entry has the file scheme. The ticket identifies fixed releases rather than a specific core commit. The tested fixed release build is cd7284b4cbbfeb507e630c1aac019f4157393acb; its jvmaccess/source/classpath.cxx contains the nine-line scheme-validation change relative to vulnerable build 0229ac93fcf0d7cbc6376066c6f35021cef002dc.

Reproduction Steps

  1. Run bash bundle/repro/reproduction_steps.sh from any directory. The script honors PRUVA_ROOT and uses the prepared project cache when available.
  2. The script downloads immutable official LibreOffice archives for 26.2.4.2 and 26.2.5, verifies/logs their SHA-256 hashes, extracts the real products, and installs required runtime libraries and a JDK if absent.
  3. It compiles an attacker-controlled JDBC driver whose static initializer writes a unique marker, generates a remote .odb containing an HTTP db:java-classpath, and generates a Calc .ods containing a persisted SQL calcext:data-mapping that points to that .odb.
  4. A local HTTP service hosts the .odb and Java class. The script opens isolated document copies with real vulnerable and fixed soffice processes: two vulnerable attempts followed by two fixed attempts.
  5. Success requires both vulnerable attempts to contain marker_present=true and the exact code-execution marker, while both fixed attempts contain marker_present=false. The script exits 0 only when this vulnerable/fixed divergence is observed.

Evidence

  • bundle/repro/vulnerable-attempt-1.txt and vulnerable-attempt-2.txt: each records marker_present=true and CVE-2026-63277_REMOTE_JDBC_CODE_EXECUTION.
  • bundle/repro/fixed-attempt-1.txt and fixed-attempt-2.txt: each records marker_present=false for the same attacker procedure.
  • bundle/repro/http-server-final.txt: records HTTP retrieval of /evil.odb and /evil/RemoteDriver.class by vulnerable Calc. There are two vulnerable retrieval sequences and no fixed retrieval of the remote class.
  • bundle/logs/product-archives.sha256: immutable official archive hashes:
    • 26.2.4.2: 810ef197e190d7804a60e0016052c46ff33792303a200fddda9d5216a64b9900
    • 26.2.5: 2f03bfb2ac9f33ea7c77331b4b7a23300fb0ed7443566046bf8b5bc51c1bed1e
  • bundle/logs/vulnerable-version.txt and fixed-version.txt: real product versions and build SHAs.
  • bundle/repro/runtime_manifest.json: strict runtime manifest binding all finalized proof artifacts and their SHA-256 hashes.
  • bundle/logs/reproduction_steps.log: full setup and diagnostic transcript. It is intentionally not listed as immutable proof because the script writes to it during execution.

Key vulnerable excerpt:

role=vulnerable attempt=1 exit_code=255
marker_present=true
marker_content_begin
CVE-2026-63277_REMOTE_JDBC_CODE_EXECUTION
marker_content_end

Key fixed-control excerpt:

role=fixed attempt=1 exit_code=255
marker_present=false

The exit code reflects intentional process-group termination after the bounded observation window, not a product crash. No sanitizer or instrumentation was used.

Recommendations / Next Steps

  • Upgrade to LibreOffice 26.2.5 or 26.8.0 and later.
  • Retain the fixed jvmaccess::ClassPath::translateToUrls policy that rejects missing, malformed, and non-file: class-path entries before creating Java URLs.
  • Add regression coverage that opens a real Calc data-mapping document with a remote .odb, rather than testing only the lower-level class-path helper.
  • Cover HTTP, HTTPS, redirecting URLs, compound class paths, case variants of URL schemes, percent-encoded input, and expansion URLs.
  • Keep a fixed negative control proving the remote .odb may be encountered but its Java class is never downloaded or initialized.
  • Consider separately applying Calc's external-link consent controls to SQL mappings and remote database documents as defense in depth.

Additional Notes

  • Idempotency: The final reproducer was executed twice consecutively after completion. Every run recreates the generated ODS/ODB/payload, allocates a fresh loopback port, uses fresh user profiles and document copies, and kills each product process group before the next attempt.
  • User-facing path: This is a production-path viewer_document proof using the official uninstrumented soffice product, not a parser or unit harness.
  • Network scope: The HTTP service binds only to 127.0.0.1; this safely reproduces the remote URL semantics while preventing exposure outside the sandbox.
  • Payload limitation: The proof class only writes a marker. That is deliberate and sufficient because it is attacker-authored Java executing through the vulnerable class loader.

CVE-2026-63277 Reproduction Transcript

The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.

Full session Replay every step — scrub the timeline or play it back.

Event 1/40
0:002:26
0:00
session startedgpt-5.6-sol · CVE-2026-63277 · REPRO-20
0:07
0:21
0:24
web search
0:32
0:34
0:36
web search
0:38
web search
0:53
0:55
web search
0:58
web search
0:59
1:47
extract_facts
no facts extracted
1:50
1:54
1:54
supportclaim_contract
2:02
2:02
2:02
2:02
2:08
2:09
2:09
2:09
2:09
2:16
2:16
2:19
web search
2:19
$docker ps --format '{{.ID}} {{.Image}}' && printf '\nTOOLS\n' && command -v libreoffice || true; java -version 2>&1 | head -3 || true; git --version
0.4s✓

TOOLS
pruva-command: 1: java: not found
git version 2.55.0
2:26
08 · How to Fix

How to Fix CVE-2026-63277

Coming soon

Step-by-step mitigation and hardening guidance for CVE-2026-63277 — configuration checks, workarounds where no patch exists, and how to verify you're protected — is on the way.

10 · FAQ

FAQ: CVE-2026-63277

Is CVE-2026-63277 exploitable?

Yes. Pruva independently reproduced CVE-2026-63277 and verified the exploit fires end-to-end in a sandboxed environment. A runnable proof-of-concept script and the full agent transcript are on this page (reproduction REPRO-2026-00374).

How severe is CVE-2026-63277?

CVE-2026-63277 is rated high severity.

How can I reproduce CVE-2026-63277?

Pruva provides a verified reproduction script on this page. Download it and run it inside an isolated environment such as a container or virtual machine — never against production. The reproduction was confirmed end-to-end by Pruva's automated agents.

Is the CVE-2026-63277 reproduction verified?

Yes. Pruva reproduced CVE-2026-63277 with high confidence in a sandboxed environment, capturing the full agent transcript and artifacts as evidence.
11 · References

References for CVE-2026-63277

Authoritative sources for CVE-2026-63277 — official vulnerability databases and the upstream advisory. Pruva's reproduction verifies the issue firsthand; these are the primary records to corroborate it.