Opening a malicious document can lead to system takeover
Description
A code execution issue in the Java integration in Apache OpenOffice allows a crafted untrusted document to trigger the execution of arbitrary, even remote, code when it is opened by the user.
This issue affects Apache OpenOffice: through 4.1.16.
This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Once 4.1.17 is released, users are recommended to upgrade to that version, which fixes the issue.
The LibreOffice suite reported this issue as CVE-2026-63277.
Severity: Critical
Thanks to the reporters for discovering this issue.
Vendor: The Apache Software Foundation
Versions Affected
All Apache OpenOffice versions 4.1.16 and older are affected.
OpenOffice.org versions may also be affected.
Mitigation
Until 4.1.17 is released, users can mitigate this issue by disabling the Java runtime integration: choose Tools - Options - OpenOffice - Java (OpenOffice - Preferences - OpenOffice - Java on macOS) and untick Use a Java runtime environment. This prevents the attack. If this is not possible, or as an extra precaution, avoid opening untrusted files entirely.
Once released, install Apache OpenOffice 4.1.17 for the latest maintenance and cumulative security fixes. Use the Apache OpenOffice download page.
Acknowledgements
The Apache OpenOffice Security Team would like to thank Rick de Jager of the V12 security team, and Thomas Rinsma and Edoardo Geraci of Codean Labs, who independently discovered and reported this issue.
Further Information
For additional information and assistance, consult the Apache OpenOffice Community Forums or make requests to the users@openoffice.apache.org public mailing list.
The latest information on Apache OpenOffice security bulletins can be found at the Bulletin Archive page.

