CVE-2026-59265: Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover

Published Oct 2, 2026
·
Updated

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user.

This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase.

Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.

Affected Software

1 affected component
Apache OpenOffice<=4.1.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache OpenOffice to a version that resolves this vulnerability.

    Fixed in 4.1.17
  2. Configuration

    Disable Java runtime integration in the Preferences dialog.

    Apache OpenOffice Java runtime integration = disabled
  3. Compensating control

    Avoid opening untrusted files entirely.

Event History

Oct 2, 2026
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
DescriptionWeakness

Frequently Asked Questions

1

What user action is required for exploitation?

The user must open a crafted, untrusted document in Apache OpenOffice. Opening that document can cause arbitrary code, including remote code, to execute.

2

Which installations are affected?

Apache OpenOffice version 4.1.16 and earlier are affected. The issue is in the product's Java runtime integration.

3

Can the issue be mitigated before an update is available?

Yes. Disable Java runtime integration through the Preferences dialog; this prevents the attack. If Java integration cannot be disabled, do not open untrusted files.

4

What version fixes the issue?

Version 4.1.17 is expected to fix the issue, but it is currently in the release candidate phase. Upgrade after that version is released.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203