Junglewise Threat Intelligence

CVE-2026-63278: LibreOffice environment variable and INI file expansion in URLs

CVE-2026-63278 · Severity: info · Published 2026-09-22

Technologies: The Document Foundation LibreOffice. Vendors: The Document Foundation.

Executive brief

LibreOffice is an office suite used to create and edit documents like spreadsheets and presentations. A flaw allows specially crafted URLs in documents to expose sensitive information such as environment variables and configuration file values when a user opens the document. An attacker could exfiltrate this data to a remote server without the user's knowledge, potentially exposing credentials, API keys, or system configuration details.

Technical details

URLs in documents could trigger environment variable and INI file value expansion, leading to information disclosure when the document is opened. A prior fix for CVE-2024-12426 failed to catch all variations of package content provider naming, allowing bypass via alternative URL naming schemes. The fix in LibreOffice 26.2.5 properly matches the package content provider URI scheme during URL validation.

Affected products

  • The Document Foundation LibreOffice before 26.2.5

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched

References

Related threats