This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase.
Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 02 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache openoffice |
|
| Vendors & Products |
Apache
Apache openoffice |
Fri, 02 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) code when opened by the user. This issue is expected to be fixed in version 4.1.17, which is in the release candidate phase. Until then, users can mitigate this issue by disabling Java runtime integration in the Preferences dialog. This prevents the attack. If this is not possible, or as an extra precaution, you can avoid opening open untrusted files entirely. Once 4.1.17 is released, upgrade to that version to fix the issue. | |
| Title | Apache OpenOffice, Apache OpenOffice: Opening a malicious document can lead to system takeover | |
| Weaknesses | CWE-426 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-02T21:07:25.674Z
Reserved: 2026-07-04T15:35:39.146Z
Link: CVE-2026-59265
No data.
Status : Deferred
Published: 2026-10-02T18:17:03.917
Modified: 2026-10-02T22:16:54.533
Link: CVE-2026-59265
No data.
OpenCVE Enrichment
Updated: 2026-10-02T19:00:05Z
