CVE-2026-63277: Verified Reproduction
CVE-2026-63277: LibreOffice Calc RCE via calcext:data-mappings, sql provider and jdbc connector — document-named Java DB driver loaded from a remote class path URL on open
CVE-2026-63277 is verified against the affected target. Vulnerability class: RCE. This high reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00374.
What Is CVE-2026-63277?
CVE-2026-63277 is a high-severity RCE vulnerability. Pruva has independently reproduced it and publishes a verified, runnable proof-of-concept (reproduction REPRO-2026-00374).
CVE-2026-63277 Severity
CVE-2026-63277 is rated high severity.
High — serious impact or readily exploitable. Prioritize remediation.
How to Reproduce CVE-2026-63277
pruva-verify REPRO-2026-00374 curl -O https://www.pruva.dev/api/v1/reproductions/REPRO-2026-00374/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Proof of Reproduction for CVE-2026-63277
- reached the target end-to-end
- full exploit chain demonstrated
- on the real production code path
- high confidence
- the upstream fix blocks the same trigger
Crafted .ods data mapping, remote .odb JDBC settings, Java driver class name, and HTTP Java class path
- LibreOffice Calc document open
- calcext:data-mapping
- SQLDataProvider
- remote ODB
- JDBC class loader
How the agent worked
Root Cause and Exploit Chain for CVE-2026-63277
LibreOffice Calc 26.2.4.2 and earlier can automatically process a persisted calcext:data-mappings SQL data provider while opening an attacker-crafted .ods. The mapping's identifier can point to a remote .odb database document. That database document controls the JDBC driver class name and JavaDriverClassPath; vulnerable LibreOffice passes an HTTP class-path URL into its Java class loader without restricting it to local files. As a result, opening the spreadsheet causes Calc to retrieve and initialize an attacker-controlled Java class. This run demonstrated that behavior through the real soffice document-open path and recorded target-local code-execution markers.
- Affected component: LibreOffice Calc external data mappings, SQL data provider, database document loader, JDBC connector, and
jvmaccess::ClassPath. - Affected versions: Reproduced with official LibreOffice 26.2.4.2 (build commit
0229ac93fcf0d7cbc6376066c6f35021cef002dc). The vendor states the issue is fixed in 26.2.5 and 26.8.0. - Fixed control: Official LibreOffice 26.2.5.2 (build commit
cd7284b4cbbfeb507e630c1aac019f4157393acb). - Risk: High. A malicious spreadsheet can execute Java bytecode with the privileges of the LibreOffice user when the document is opened. The executed Java code can access files, processes, and network resources available to that account.
Impact Parity
- Disclosed/claimed maximum impact: Code execution from a crafted Calc document.
- Reproduced impact: Attacker-controlled Java code execution in the real LibreOffice process path. The remote driver's static initializer wrote
CVE-2026-63277_REMOTE_JDBC_CODE_EXECUTIONto a unique marker for each vulnerable attempt. - Parity:
full - Not demonstrated: No additional privilege escalation was attempted or claimed. The payload intentionally used a harmless file marker rather than launching a shell.
Root Cause
The ODS importer creates an ExternalDataSource for every persisted calcext:data-mapping. The vulnerable import path refreshes each mapping immediately when the mapping context is destroyed. For calcext:provider="org.libreoffice.calc.sql", SQLDataProvider parses an ID of the form <table>@<database> and gives <database> to com.sun.star.sdb.DatabaseContext::getByName. If the name is not registered, the database context treats it as a URL and loads the referenced .odb.
The remotely supplied .odb can persist:
db:connection-resourceselecting a JDBC URL;db:java-driver-classselecting an attacker-defined driver class; anddb:java-classpathselecting where that class is loaded from.
In vulnerable builds, jvmaccess::ClassPath::translateToUrls converts every class-path entry into a Java URL without constraining its scheme. Therefore an HTTP entry reaches a Java class loader, which downloads and initializes the selected JDBC driver. Java class initialization is already arbitrary code execution; it happens before a successful database query is necessary.
The fixed code adds URL parsing in jvmaccess/source/classpath.cxx and raises IllegalArgumentException unless every Java class-path entry has the file scheme. The ticket identifies fixed releases rather than a specific core commit. The tested fixed release build is cd7284b4cbbfeb507e630c1aac019f4157393acb; its jvmaccess/source/classpath.cxx contains the nine-line scheme-validation change relative to vulnerable build 0229ac93fcf0d7cbc6376066c6f35021cef002dc.
Reproduction Steps
- Run
bash bundle/repro/reproduction_steps.shfrom any directory. The script honorsPRUVA_ROOTand uses the prepared project cache when available. - The script downloads immutable official LibreOffice archives for 26.2.4.2 and 26.2.5, verifies/logs their SHA-256 hashes, extracts the real products, and installs required runtime libraries and a JDK if absent.
- It compiles an attacker-controlled JDBC driver whose static initializer writes a unique marker, generates a remote
.odbcontaining an HTTPdb:java-classpath, and generates a Calc.odscontaining a persisted SQLcalcext:data-mappingthat points to that.odb. - A local HTTP service hosts the
.odband Java class. The script opens isolated document copies with real vulnerable and fixedsofficeprocesses: two vulnerable attempts followed by two fixed attempts. - Success requires both vulnerable attempts to contain
marker_present=trueand the exact code-execution marker, while both fixed attempts containmarker_present=false. The script exits 0 only when this vulnerable/fixed divergence is observed.
Evidence
bundle/repro/vulnerable-attempt-1.txtandvulnerable-attempt-2.txt: each recordsmarker_present=trueandCVE-2026-63277_REMOTE_JDBC_CODE_EXECUTION.bundle/repro/fixed-attempt-1.txtandfixed-attempt-2.txt: each recordsmarker_present=falsefor the same attacker procedure.bundle/repro/http-server-final.txt: records HTTP retrieval of/evil.odband/evil/RemoteDriver.classby vulnerable Calc. There are two vulnerable retrieval sequences and no fixed retrieval of the remote class.bundle/logs/product-archives.sha256: immutable official archive hashes:- 26.2.4.2:
810ef197e190d7804a60e0016052c46ff33792303a200fddda9d5216a64b9900 - 26.2.5:
2f03bfb2ac9f33ea7c77331b4b7a23300fb0ed7443566046bf8b5bc51c1bed1e
- 26.2.4.2:
bundle/logs/vulnerable-version.txtandfixed-version.txt: real product versions and build SHAs.bundle/repro/runtime_manifest.json: strict runtime manifest binding all finalized proof artifacts and their SHA-256 hashes.bundle/logs/reproduction_steps.log: full setup and diagnostic transcript. It is intentionally not listed as immutable proof because the script writes to it during execution.
Key vulnerable excerpt:
role=vulnerable attempt=1 exit_code=255
marker_present=true
marker_content_begin
CVE-2026-63277_REMOTE_JDBC_CODE_EXECUTION
marker_content_end
Key fixed-control excerpt:
role=fixed attempt=1 exit_code=255
marker_present=false
The exit code reflects intentional process-group termination after the bounded observation window, not a product crash. No sanitizer or instrumentation was used.
Recommendations / Next Steps
- Upgrade to LibreOffice 26.2.5 or 26.8.0 and later.
- Retain the fixed
jvmaccess::ClassPath::translateToUrlspolicy that rejects missing, malformed, and non-file:class-path entries before creating Java URLs. - Add regression coverage that opens a real Calc data-mapping document with a remote
.odb, rather than testing only the lower-level class-path helper. - Cover HTTP, HTTPS, redirecting URLs, compound class paths, case variants of URL schemes, percent-encoded input, and expansion URLs.
- Keep a fixed negative control proving the remote
.odbmay be encountered but its Java class is never downloaded or initialized. - Consider separately applying Calc's external-link consent controls to SQL mappings and remote database documents as defense in depth.
Additional Notes
- Idempotency: The final reproducer was executed twice consecutively after completion. Every run recreates the generated ODS/ODB/payload, allocates a fresh loopback port, uses fresh user profiles and document copies, and kills each product process group before the next attempt.
- User-facing path: This is a production-path
viewer_documentproof using the official uninstrumentedsofficeproduct, not a parser or unit harness. - Network scope: The HTTP service binds only to
127.0.0.1; this safely reproduces the remote URL semantics while preventing exposure outside the sandbox. - Payload limitation: The proof class only writes a marker. That is deliberate and sufficient because it is attacker-authored Java executing through the vulnerable class loader.
CVE-2026-63277 Reproduction Transcript
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Full session Replay every step — scrub the timeline or play it back.
docker ps --format '{{.ID}} {{.Image}}' && printf '\nTOOLS\n' && command -v libreoffice || true; java -version 2>&1 | head -3 || true; git --versionTOOLS pruva-command: 1: java: not found git version 2.55.0
Artifacts and Evidence for CVE-2026-63277
Scripts, logs, diffs, and output captured during the reproduction.
How to Fix CVE-2026-63277
FAQ: CVE-2026-63277
Is CVE-2026-63277 exploitable?
How severe is CVE-2026-63277?
How can I reproduce CVE-2026-63277?
Is the CVE-2026-63277 reproduction verified?
References for CVE-2026-63277
Authoritative sources for CVE-2026-63277 — official vulnerability databases and the upstream advisory. Pruva's reproduction verifies the issue firsthand; these are the primary records to corroborate it.