CVE-2026-59265
OpenOffice Java document code execution
Opening a crafted document in Apache OpenOffice 4.1.16 or earlier can run arbitrary code through the Java integration. Apache calls it critical. No CVSS score is published, and 4.1.17 is still a release candidate.
- CVSS
- Unknown
- Vector
- Not recorded
- Class
- RCE
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache OpenOffice
- Affected
- Apache OpenOffice 4.1.16 and earlier.
- Fixed
- Expected in 4.1.17, which Apache says is still a release candidate. No finished release is available yet.
- CWE
- CWE-426
- Published
- 2 Oct 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-59265 is a code-execution bug in the Java integration of Apache OpenOffice 4.1.16 and earlier. Apache's note on 2 October 2026 says a crafted document can run arbitrary code, including remote code, when a person opens it. The weakness is CWE-426. Apache labels the severity critical. NVD has no CVSS score for it, so this record does not invent one.
The bug is not a remote, unauthenticated service flaw. It needs a document to be opened. ThreatWire has not confirmed a public proof of concept, and CISA has not listed the CVE. The status stays No PoC.
Apache says the fix is expected in 4.1.17, which is still a release candidate. Until that version is actually released, the published workaround is to disable Java runtime integration in Preferences. Avoiding untrusted documents is the extra precaution Apache also names. The finders credited in the advisory are Thomas Rinsma and Edoardo Geraci of Codean Labs, and Rick de Jager.
Other Apache products shipped unrelated fixes in the same period. They are not this CVE and they are not recorded here.