8.8
CVE-2026-59265
- EPSS 0.22%
- Veröffentlicht 02.10.2026 17:34:06
- Zuletzt bearbeitet 06.10.2026 14:17:45
- Erkennungen
Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover
A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt
Apache OpenOffice
Default Statusunaffected
Version <=
4.1.16
Version
0
Status
affected
HerstellerApache Software Foundation
≫
Produkt
Apache OpenOffice
Default Statusunaffected
Version
0
Version <
95923fd437e06edd38a4f0e139a27c755a6f3ba6
Status
affected
Version
0
Version <
181421139242694b309751fb666406eddc203c50
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.118 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-426 Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://github.com/apache/openoffice/commit/c699bed3f75e79bd64ddec9dec49f9e210eed281.patch
https://github.com/apache/openoffice/commit/95923fd437e06edd38a4f0e139a27c755a6f3ba6.patch
https://lists.apache.org/thread.html/svfdc1jtpqlw7mo6lgg9fthcmf754pl5
http://www.openwall.com/lists/oss-security/2026/10/02/2