
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8358 is a heap buffer overflow vulnerability in LibreOffice Calc's tracked-changes importer, classified as CWE-787 (Out-of-bounds Write) and CWE-843 (Type Confusion). It affects LibreOffice versions in the 25.8 series prior to 25.8.7 and the 26.2 series prior to 26.2.4, developed by The Document Foundation. The vulnerability was published on June 15, 2026, with a patch released the same day. It carries a CVSS v4.0 base score of 5.4 (Medium) (GitHub Advisory, LibreOffice Advisory).
The root cause is a type confusion (CWE-843) combined with an out-of-bounds write (CWE-787) in LibreOffice Calc's spreadsheet import logic for tracked changes. When a malicious document reuses the same change identifier for two different types of tracked changes, the importer incorrectly treats one change object as a different, larger type and writes heap memory past the end of the allocated buffer. Exploitation requires local access and passive user interaction — specifically, a victim must open a crafted spreadsheet file. Fixed versions reject records with duplicate change identifiers during import (GitHub Advisory, LibreOffice Advisory).
Successful exploitation can result in a heap buffer overflow that may lead to arbitrary code execution with the privileges of the LibreOffice process, as well as application crashes (high availability impact). There is also a limited risk of confidentiality and integrity compromise within the vulnerable system. Because exploitation is confined to the local context of the user opening the file, lateral movement potential is limited, though code execution under the user's account could enable further post-exploitation activity (GitHub Advisory, LibreOffice Advisory).
As of the time of disclosure, there is no confirmed public proof-of-concept exploit and no evidence of active in-the-wild exploitation; the CVSS v4.0 exploit maturity is rated "Proof of Concept" in the scoring vector, though Feedly's executive summary notes no public PoC exists (GitHub Advisory). The EPSS score is approximately 0.13–0.17%, placing it in a low percentile for near-term exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
soffice, soffice.bin) spawning unexpected child processes (e.g., shell interpreters, network utilities like curl, wget, or python) following document open events.soffice with memory-related signals (e.g., SIGSEGV, SIGABRT).The Document Foundation has released patched versions: 25.8.7 (25.8 series) and 26.2.4 (26.2 series), which reject spreadsheet records with duplicate change identifiers during import. Users should upgrade to one of these fixed versions immediately. As a temporary workaround until patching is possible, avoid opening spreadsheet documents from untrusted or unknown sources in LibreOffice Calc (LibreOffice Advisory, GitHub Advisory). Debian and SUSE have also issued updated packages for their distributions (Linux Compatible).
The vulnerability received routine coverage from vulnerability tracking platforms and security feeds shortly after disclosure on June 15, 2026. Debian and SUSE issued updated packages for their distributions, indicating prompt downstream response (Linux Compatible). Tenable published Nessus detection plugins (IDs 321128, 321142, 321496) to assist organizations in identifying vulnerable installations (Tenable). No significant researcher commentary or social media debate beyond standard CVE tracking activity has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."