LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

A critical vulnerability has been discovered in LibreOffice and OpenOffice, two popular open-source office suite software packages. The flaw allows malicious spreadsheets to run code without triggering warning alerts about macros, potentially leading to serious security breaches. This issue affects millions of users worldwide who rely on these suites for work and personal projects.

The vulnerability, identified as CVE-2026-1234, resides in the way LibreOffice and OpenOffice handle certain spreadsheet formulas. When a maliciously crafted formula is executed, it can bypass the normal macro warning mechanism, allowing the code to run automatically without user intervention. This could enable attackers to exploit system vulnerabilities, steal sensitive data, or even take control of entire networks.

LibreOffice and OpenOffice are widely used across various industries, from small businesses to large enterprises. The affected software includes LibreOffice 7.x and OpenOffice 4.x, which have a combined user base exceeding 100 million individuals. The vulnerability affects both Windows and Linux platforms, making it a significant concern for security professionals.

The exploit mechanism relies on the use of specific spreadsheet formulas that manipulate the underlying document structure. When these formulas are executed, they can create temporary files or modify existing ones in a way that allows malicious code to run without triggering the macro warning alert. This is particularly insidious because it enables attackers to conceal their malicious activities from unsuspecting users.

The discovery of this vulnerability highlights the ongoing challenge of ensuring software security in the face of increasing complexity and interconnectedness. As more organizations rely on open-source solutions, the importance of rigorous testing and patching becomes increasingly critical. Users are advised to update their LibreOffice and OpenOffice installations immediately and exercise caution when opening unsolicited spreadsheets.

In light of this vulnerability, it is essential for users to maintain a secure computing environment by keeping software up-to-date and being vigilant about suspicious documents. This includes avoiding the use of unsolicited spreadsheets, especially from unknown sources. By taking proactive steps to address potential security threats, individuals can significantly reduce their exposure to malicious attacks.


Source: The Hacker News — 2026-10-06