Out-of-bounds write in LibreOffice - CVE-2026-4430
Published: June 1, 2026
LibreOffice
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in AgileEngine when parsing crafted OOXML documents with mismatched encryption salt parameters. A remote attacker can trick the victim into opening a specially crafted document to execute arbitrary code.
User interaction is required to open a crafted document.