8.8

CVE-2026-59265

Medienbericht

Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user.



This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase.



Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt Apache OpenOffice
Default Statusunaffected
Version <= 4.1.16
Version 0
Status affected
HerstellerApache Software Foundation
≫
Produkt Apache OpenOffice
Default Statusunaffected
Version 0
Version < 95923fd437e06edd38a4f0e139a27c755a6f3ba6
Status affected
Version 0
Version < 181421139242694b309751fb666406eddc203c50
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.118
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-426 Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
06.10.2026 14:04
https://github.com/apache/openoffice/commit/c699bed3f75e79bd64ddec9dec49f9e210eed281.patch
https://github.com/apache/openoffice/commit/95923fd437e06edd38a4f0e139a27c755a6f3ba6.patch
https://lists.apache.org/thread.html/svfdc1jtpqlw7mo6lgg9fthcmf754pl5
http://www.openwall.com/lists/oss-security/2026/10/02/2