5.4
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:P
Description
Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.
This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.
Basic Information
ID
CVE-2026-4430
Source
Document Fdn.
Published
May 7, 2026 at 07:16
Affected Product
Vendor
The Document Foundation
Product
LibreOffice
Version
26.2
Affected Versions
The Document Foundation LibreOffice 26.2
The Document Foundation LibreOffice 25.8
The Document Foundation LibreOffice 25.8