Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-59265

OpenOffice Java document code execution

Opening a crafted document in Apache OpenOffice 4.1.16 or earlier can run arbitrary code through the Java integration. Apache calls it critical. No CVSS score is published, and 4.1.17 is still a release candidate.

CVSS
Unknown
Vector
Not recorded
Class
RCE
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache OpenOffice
Affected
Apache OpenOffice 4.1.16 and earlier.
Fixed
Expected in 4.1.17, which Apache says is still a release candidate. No finished release is available yet.
Published
2 Oct 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-59265 is a code-execution bug in the Java integration of Apache OpenOffice 4.1.16 and earlier. Apache's note on 2 October 2026 says a crafted document can run arbitrary code, including remote code, when a person opens it. The weakness is CWE-426. Apache labels the severity critical. NVD has no CVSS score for it, so this record does not invent one.

The bug is not a remote, unauthenticated service flaw. It needs a document to be opened. ThreatWire has not confirmed a public proof of concept, and CISA has not listed the CVE. The status stays No PoC.

Apache says the fix is expected in 4.1.17, which is still a release candidate. Until that version is actually released, the published workaround is to disable Java runtime integration in Preferences. Avoiding untrusted documents is the extra precaution Apache also names. The finders credited in the advisory are Thomas Rinsma and Edoardo Geraci of Codean Labs, and Rick de Jager.

Other Apache products shipped unrelated fixes in the same period. They are not this CVE and they are not recorded here.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-59265