CVE-2026-59265 Details
Description
A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.
A code execution vulnerability has been identified in the Java integration of Apache OpenOffice versions through 4.1.16. This issue allows a crafted untrusted document to execute arbitrary code, including remote code, when opened by the user. The vulnerability arises from insufficient validation of URLs in the classpath, which can be exploited by malicious documents to trigger code execution.
Users can disable Java runtime integration in the Preferences dialog to mitigate this issue. If this is not possible, untrusted files should not be opened. Once Apache OpenOffice version 4.1.17 is released, users should upgrade to that version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 2, 2026CISA-ADP
Assessed Oct 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/10/02/2 | CVE | AdvisoryMailing ListRemedy |
| https://github.com/apache/openoffice/commit/95923fd437e06edd38a4f0e139a27c755a6f3ba6.patch | [email protected] | Source CodeVendor |
| https://github.com/apache/openoffice/commit/c699bed3f75e79bd64ddec9dec49f9e210eed281.patch | [email protected] | Source CodeVendor |
| https://lists.apache.org/thread.html/svfdc1jtpqlw7mo6lgg9fthcmf754pl5 | [email protected] | AdvisoryMailing ListRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Apache OpenOffice | <= 4.1.16 (semver) < 95923fd437e06edd38a4f0e139a27c755a6f3ba6 < 181421139242694b309751fb666406eddc203c50 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 3, 2026 | CVE Modified | CISA-ADP |
| Oct 2, 2026 | CVE Modified | CVE |
| Oct 2, 2026 | New CVE Received | [email protected] |
Volerion