CVE-2026-63266: Arbitrary file write via calcext:data-mappings, sql provider and Firebird backup functionality
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to. In fixed versions an embedded Firebird database can open or create files only inside its own private directory.
Affected Software
Event History
Frequently Asked Questions
What must an attacker provide to trigger the issue?
An attacker would need to provide a Calc document containing a saved external data link that uses calcext:data-mappings with the SQL provider and an embedded Firebird database.
What access does successful exploitation give the attacker?
The embedded Firebird database could write a file to any location that the user opening the document is permitted to write to. The described impact is arbitrary file creation or overwrite within that user's write permissions.
How do fixed versions limit the risk?
In fixed versions, an embedded Firebird database can open or create files only within its own private directory.