Skip to content
THREATWIRE

News

OpenOffice Java bug has no released fix

CVE-2026-59265 can run code when a person opens a crafted document in Apache OpenOffice 4.1.16 or earlier. There is no CVSS score, no KEV listing, and no finished 4.1.17 release.

Critical

Published 5 Oct 2026 · Updated 5 Oct 2026

What happened

Apache published CVE-2026-59265 on 2 October 2026. Dave Fisher sent the note to oss-security that afternoon. The Apache OpenOffice bulletin uses the same text: a code-execution issue in the Java integration lets a crafted document run arbitrary code, including code fetched from elsewhere, when a person opens the file.

Apache rates it critical. NVD does not publish a CVSS number for this CVE. The ThreatWire record leaves the score empty rather than inventing one.

Who is affected

Every Apache OpenOffice release through 4.1.16 is in scope. The bulletin also says older OpenOffice.org builds may be affected. LibreOffice tracked the same class of issue as CVE-2026-63277. That is a different product and a different CVE. It is context, not this record.

The bug is not a listening service. Someone has to open the document, and Java integration has to be enabled. A machine that never opens untrusted files, or that already has Java turned off inside OpenOffice, is outside the path the bulletin describes.

What is confirmed

The finders named by Apache are Thomas Rinsma and Edoardo Geraci of Codean Labs, and Rick de Jager of the V12 security team. They reported it independently. The bulletin’s mitigation is specific: Tools, Options, OpenOffice, Java, and untick “Use a Java runtime environment.” On macOS the same control is under OpenOffice, Preferences, OpenOffice, Java. Apache says that setting prevents the attack.

What is not confirmed

There is no finished fix a user can download as 4.1.17. Apache says that version should contain the patch and that it is still a release candidate. Source commits exist. A release candidate and a commit are not a shipped installer. ThreatWire has not confirmed a public proof of concept, and CISA has not listed the CVE. The status stays No PoC. It is not a 0-day: the issue is a document the user opens, and exploitation before a fix is not what the advisory reports.

Other Apache security releases from the same week are other products. They are not folded into this record.

What to do

Until 4.1.17 is actually released, turn off Java runtime integration with the menu path above, and do not open untrusted documents in OpenOffice. When the finished 4.1.17 build is on the Apache download page, that is the upgrade. Installing a release candidate is not the recommendation in the bulletin.

Sources: the Apache OpenOffice page for CVE-2026-59265, Dave Fisher’s oss-security note of 2 October 2026, and NVD.

Related CVEs

Sources

Share on X@threatwire_https://www.threatwire.tech/news/openoffice-java-bug-has-no-released-fix