๐Ÿ” CVE Alert

CVE-2026-63278

UNKNOWN 0.0

Package URLs can be used to exfiltrate arbitrary INI file values and environment variables

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-12426 did not recognise every way of naming the package content provider, so a URL that named it differently still reached the expansion. In fixed versions the package content provider is matched when the URL is checked.

CWE CWE-200
Vendor the document foundation
Product libreoffice
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for the document foundation libreoffice

Be the first to know when new unknown vulnerabilities affecting the document foundation libreoffice are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The Document Foundation / LibreOffice
26.2 < < 26.2.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
libreoffice.org: https://www.libreoffice.org/about-us/security/advisories/cve-2026-63278

Credits

๐Ÿ” Darren Xuan of Tanto Security Caolรกn McNamara of Collabora Productivity