NewsSecurity Vulnerabilities

Critical Apache OpenOffice Flaw Could Allow System Takeover (CVE-2026-59265)

A critical security vulnerability in Apache OpenOffice could allow an attacker to execute arbitrary code on a vulnerable computer simply by getting a victim to open a specially crafted document.

Tracked as CVE-2026-59265, the vulnerability affects the Java integration within Apache OpenOffice and was publicly disclosed on 2 October 2026. Apache describes the issue as a code execution vulnerability that can potentially result in a complete system takeover.

Malicious documents

The vulnerability affects Apache OpenOffice versions through 4.1.16. According to the Apache Software Foundation, a specially crafted untrusted document can trigger arbitrary code execution when it is opened by a user.

The vulnerability is associated with OpenOffice’s Java integration. An attacker could potentially construct a malicious document and distribute it through email, websites, file-sharing services or other methods designed to persuade a user to open the file.

If successfully exploited, the attacker could execute arbitrary code, including code originating remotely, potentially giving them control over the affected system.

This makes the vulnerability particularly significant because exploitation requires user interaction, rather than an attacker necessarily having direct network access to the target computer.

Affected versions

The vulnerability affects:

  • Apache OpenOffice 4.1.16 and earlier
  • OpenOffice versions before the relevant security fixes identified by the Apache project

Apache has indicated that the vulnerability is expected to be fixed in OpenOffice 4.1.17, which was in release-candidate status when the vulnerability was disclosed.

At the time of disclosure, vulnerability databases had not assigned a CVSS score to CVE-2026-59265. Rapid7 also listed the vulnerability as not currently present in the CISA Known Exploited Vulnerabilities catalogue.

How the attack works

The attack relies on a malicious document being opened by the victim.

A typical attack could involve an attacker creating a specially prepared OpenOffice document and convincing a target to open it. When the document is processed by the vulnerable Java integration, it can cause arbitrary code to execute.

This could potentially allow an attacker to:

  • Run malicious programs
  • Install additional malware
  • Steal information
  • Modify or delete files
  • Establish persistence on the computer
  • Use the compromised machine as a starting point for further attacks

The actual impact would depend on the permissions available to the OpenOffice process and the security controls deployed on the affected system.

Java integration provides temporary mitigation

Apache has provided a mitigation for users who cannot immediately upgrade.

The project recommends disabling Java runtime integration through the OpenOffice Preferences dialog. According to Apache, disabling Java runtime integration prevents the attack.

Users should also avoid opening untrusted documents until a fixed release is installed.

The recommended long-term solution is to upgrade to Apache OpenOffice 4.1.17 once the fixed release becomes available.

What users should do

Organisations using Apache OpenOffice should identify installations running version 4.1.16 or earlier and prepare to update them.

Until the fixed release is available, administrators can consider disabling Java runtime integration and should reinforce controls around opening documents received from unknown or untrusted sources.

Email filtering and endpoint security controls can also help reduce the likelihood of malicious documents reaching users, although these measures should not be considered a replacement for updating vulnerable software.

CVE-2026-59265 demonstrates why document files remain an important attack vector. Office documents are routinely exchanged by businesses and individuals, and vulnerabilities that turn apparently harmless files into a route to code execution can provide attackers with a practical way into otherwise protected systems.

For now, users should treat unexpected OpenOffice documents with caution, disable Java integration where practical, and upgrade to the fixed OpenOffice release as soon as it is available.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.