This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase.
Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 02 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache openoffice |
|
| Vendors & Products |
Apache
Apache openoffice |
Fri, 02 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue. | |
| Title | Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover | |
| Weaknesses | CWE-426 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-06T13:09:51.680Z
Reserved: 2026-07-04T15:35:39.146Z
Link: CVE-2026-59265
Updated: 2026-10-02T21:07:25.674Z
Status : Deferred
Published: 2026-10-02T18:17:03.917
Modified: 2026-10-06T14:17:45.660
Link: CVE-2026-59265
No data.
OpenCVE Enrichment
Updated: 2026-10-07T07:00:14Z
-
CWE-426
Untrusted Search Path