CVE-2026-4430: Heap Buffer Overflow in AgileEngine
Last updated 21 May 2026
Other sources
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libreofficeto a version that resolves this vulnerability.Fixed in 4:7.4.7-1+deb12u12Fixed in 4:7.4.7-1+deb12u11Fixed in 4:25.2.3-2+deb13u4Fixed in 4:26.2.3.2-2Fixed in 4:26.2.4.2-1 - Upgrade
Upgrade
LibreOfficeto a version that resolves this vulnerability.Fixed in 26.2.3 - Upgrade
Upgrade
LibreOfficeto a version that resolves this vulnerability.Fixed in 25.8.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4430?
CVE-2026-4430 is categorized as a high severity vulnerability due to its potential for remote code execution via heap buffer overflow.
How do I fix CVE-2026-4430?
To fix CVE-2026-4430, you should update LibreOffice to version 26.2.3 or later, or to version 25.8.7 or later.
What impact does CVE-2026-4430 have on data security?
CVE-2026-4430 can lead to unauthorized access and manipulation of data through crafted OOXML documents.
Which versions of LibreOffice are affected by CVE-2026-4430?
LibreOffice versions from 26.2 before 26.2.3 and from 25.8 before 25.8.7 are affected by CVE-2026-4430.
Can CVE-2026-4430 be exploited remotely?
Yes, CVE-2026-4430 can be exploited remotely through specially crafted documents shared via email or other means.