CVE-2026-4430

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

History

08 May 2026, 16:48

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://www.libreoffice.org/about-us/security/advisories/cve-2026-4430 - () https://www.libreoffice.org/about-us/security/advisories/cve-2026-4430 - Vendor Advisory
CPE cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
First Time Libreoffice
Libreoffice libreoffice

07 May 2026, 14:52

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 08:16

Updated : 2026-05-08 16:48


NVD link : CVE-2026-4430

Mitre link : CVE-2026-4430

CVE.ORG link : CVE-2026-4430


JSON object : View

Products Affected

libreoffice

  • libreoffice
CWE
CWE-787

Out-of-bounds Write