CVE-2026-8358
LibreOffice vulnerability analysis and mitigation

Overview

CVE-2026-8358 is a heap buffer overflow vulnerability in LibreOffice Calc's tracked-changes importer, classified as CWE-787 (Out-of-bounds Write) and CWE-843 (Type Confusion). It affects LibreOffice versions in the 25.8 series prior to 25.8.7 and the 26.2 series prior to 26.2.4, developed by The Document Foundation. The vulnerability was published on June 15, 2026, with a patch released the same day. It carries a CVSS v4.0 base score of 5.4 (Medium) (GitHub Advisory, LibreOffice Advisory).

Technical details

The root cause is a type confusion (CWE-843) combined with an out-of-bounds write (CWE-787) in LibreOffice Calc's spreadsheet import logic for tracked changes. When a malicious document reuses the same change identifier for two different types of tracked changes, the importer incorrectly treats one change object as a different, larger type and writes heap memory past the end of the allocated buffer. Exploitation requires local access and passive user interaction — specifically, a victim must open a crafted spreadsheet file. Fixed versions reject records with duplicate change identifiers during import (GitHub Advisory, LibreOffice Advisory).

Impact

Successful exploitation can result in a heap buffer overflow that may lead to arbitrary code execution with the privileges of the LibreOffice process, as well as application crashes (high availability impact). There is also a limited risk of confidentiality and integrity compromise within the vulnerable system. Because exploitation is confined to the local context of the user opening the file, lateral movement potential is limited, though code execution under the user's account could enable further post-exploitation activity (GitHub Advisory, LibreOffice Advisory).

Exploitability

As of the time of disclosure, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation; the CVSS v4.0 exploit maturity is rated "Proof of Concept" in the scoring vector, though Feedly's executive summary notes no public PoC exists (GitHub Advisory). The EPSS score is approximately 0.13–0.17%, placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Craft a malicious spreadsheet: Create a spreadsheet document (e.g., ODS or compatible format) that contains tracked changes where the same change identifier is assigned to two different types of tracked change records.
  2. Deliver the document: Distribute the malicious file to a target via email attachment, file share, or download link, relying on social engineering to prompt the victim to open it in LibreOffice Calc.
  3. Trigger the import: When the victim opens the file, LibreOffice Calc's tracked-changes importer processes the duplicate change identifier, causing a type confusion — the importer treats one change object as a larger type.
  4. Heap buffer overflow: The importer writes data past the end of the allocated heap buffer for the misidentified change object, potentially corrupting adjacent heap memory.
  5. Achieve code execution or crash: Depending on heap layout and memory state, the overflow may be leveraged to redirect execution flow and run arbitrary code with the privileges of the LibreOffice process, or cause a denial-of-service crash (GitHub Advisory, LibreOffice Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited spreadsheet files (ODS, XLSX, etc.) in user download or temp directories; files with unusual tracked-change metadata containing duplicate change identifiers.
  • Process: LibreOffice Calc (soffice, soffice.bin) spawning unexpected child processes (e.g., shell interpreters, network utilities like curl, wget, or python) following document open events.
  • Logs: Application crash logs or core dumps associated with the LibreOffice process after opening a spreadsheet; system logs showing abnormal termination of soffice with memory-related signals (e.g., SIGSEGV, SIGABRT).
  • Network: Outbound network connections initiated by the LibreOffice process to unknown external hosts shortly after a document is opened, which may indicate post-exploitation activity.

Mitigation and workarounds

The Document Foundation has released patched versions: 25.8.7 (25.8 series) and 26.2.4 (26.2 series), which reject spreadsheet records with duplicate change identifiers during import. Users should upgrade to one of these fixed versions immediately. As a temporary workaround until patching is possible, avoid opening spreadsheet documents from untrusted or unknown sources in LibreOffice Calc (LibreOffice Advisory, GitHub Advisory). Debian and SUSE have also issued updated packages for their distributions (Linux Compatible).

Community reactions

The vulnerability received routine coverage from vulnerability tracking platforms and security feeds shortly after disclosure on June 15, 2026. Debian and SUSE issued updated packages for their distributions, indicating prompt downstream response (Linux Compatible). Tenable published Nessus detection plugins (IDs 321128, 321142, 321496) to assist organizations in identifying vulnerable installations (Tenable). No significant researcher commentary or social media debate beyond standard CVE tracking activity has been observed.

Additional resources


SourceThis report was generated using AI

Related LibreOffice vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8358MEDIUM5.4
  • LibreOffice logoLibreOffice
  • autocorr-cs
NoYesJun 15, 2026
CVE-2026-8357MEDIUM5.4
  • LibreOffice logoLibreOffice
  • libreoffice-help-el
NoYesJun 15, 2026
CVE-2026-8356MEDIUM5.4
  • LibreOffice logoLibreOffice
  • libreoffice-l10n-hi
NoYesJun 15, 2026
CVE-2026-6047MEDIUM5.4
  • LibreOffice logoLibreOffice
  • libreoffice-l10n-es
NoYesJun 15, 2026
CVE-2026-6045MEDIUM5.4
  • LibreOffice logoLibreOffice
  • autocorr-pt
NoYesJun 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management