CVE-2026-4430
Heap Buffer Overflow in AgileEngine
Description
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
In plain language
AI Worth attentionThis is a bug in LibreOffice that can be triggered when a user opens a specially crafted document, potentially leading to serious impact on the computer; a typical small business should act if staff open documents from unknown sources.
CVE-2026-4430 is a heap buffer overflow in LibreOffice triggered by processing maliciously crafted OOXML documents with mismatched encryption salt parameters upon user document open, enabling potential code execution or system compromise without any login.
What to do now
- Check whether you use LibreOffice and which version is installed on your computers.
- If you’re on LibreOffice 25.8 before 25.8.7.0 or 26.2 before 26.2.3, upgrade now.
- Update LibreOffice to the fixed version: 25.8.7.0 (or later where available) from your usual software update method or installer.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-4430 and every CVE in our database. Create a free account — no credit card required.
Create Free Account