📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global general Artificial Intelligence and Software Development LOW 49m Global general Artificial Intelligence and Cybersecurity MEDIUM 1h Global malware Software Development / Technology HIGH 1h Global vulnerability Information Technology HIGH 2h Global data_breach Water Utilities / Critical Infrastructure HIGH 2h Global general Cybersecurity Services HIGH 2h Global data_breach Pharmaceutical HIGH 3h Global vulnerability Technology, Artificial Intelligence CRITICAL 4h Global vulnerability Information Technology CRITICAL 4h Global phishing Gaming and Entertainment HIGH 4h Global general Artificial Intelligence and Software Development LOW 49m Global general Artificial Intelligence and Cybersecurity MEDIUM 1h Global malware Software Development / Technology HIGH 1h Global vulnerability Information Technology HIGH 2h Global data_breach Water Utilities / Critical Infrastructure HIGH 2h Global general Cybersecurity Services HIGH 2h Global data_breach Pharmaceutical HIGH 3h Global vulnerability Technology, Artificial Intelligence CRITICAL 4h Global vulnerability Information Technology CRITICAL 4h Global phishing Gaming and Entertainment HIGH 4h Global general Artificial Intelligence and Software Development LOW 49m Global general Artificial Intelligence and Cybersecurity MEDIUM 1h Global malware Software Development / Technology HIGH 1h Global vulnerability Information Technology HIGH 2h Global data_breach Water Utilities / Critical Infrastructure HIGH 2h Global general Cybersecurity Services HIGH 2h Global data_breach Pharmaceutical HIGH 3h Global vulnerability Technology, Artificial Intelligence CRITICAL 4h Global vulnerability Information Technology CRITICAL 4h Global phishing Gaming and Entertainment HIGH 4h
Vulnerabilities

CVE-2026-4430

High
CWE-787 — Weakness Type
Published: May 7, 2026  ·  Modified: May 14, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters.

This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

🤖 AI Executive Summary

CVE-2026-4430 is a high-severity out-of-bounds write vulnerability in LibreOffice affecting versions 26.2 before 26.2.3 and 25.8 before 25.8.7. The vulnerability is triggered through crafted OOXML documents with malformed encryption salt parameters, potentially allowing remote code execution. While no exploit is currently available, the vulnerability poses significant risk to organizations processing untrusted documents.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 12, 2026 01:37
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi government entities (NCA, CITC), banking sector (SAMA-regulated institutions, Al Rajhi, Riyad Bank), and healthcare organizations that rely on LibreOffice for document processing. Government ministries using LibreOffice for official document handling are particularly vulnerable. The vulnerability could enable attackers to compromise systems processing sensitive documents, including classified government communications, financial records, and healthcare data. Energy sector organizations (ARAMCO, SEC) and telecommunications providers (STC, Mobily) using LibreOffice in operational environments face potential system compromise.
🏢 Affected Saudi Sectors
Government Banking Healthcare Energy Telecommunications Education Legal Services
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all systems running LibreOffice versions 26.2.0-26.2.2 and 25.8.0-25.8.6
2. Restrict document processing from untrusted sources until patching is complete
3. Disable automatic document opening in email clients
4. Implement network segmentation for systems processing OOXML documents

PATCHING GUIDANCE:
1. Upgrade LibreOffice to version 26.2.3 or later for 26.2.x branch
2. Upgrade LibreOffice to version 25.8.7 or later for 25.8.x branch
3. Test patches in non-production environment before deployment
4. Prioritize patching for systems handling government/financial documents

COMPENSATING CONTROLS (if patching delayed):
1. Implement application whitelisting for LibreOffice execution
2. Run LibreOffice in sandboxed environments using containers or virtualization
3. Disable OOXML document opening via macro security settings
4. Use document conversion tools (LibreOffice headless mode) with strict input validation
5. Monitor file access patterns for suspicious OOXML processing

DETECTION RULES:
1. Monitor for LibreOffice process crashes when processing OOXML files
2. Alert on OOXML files with unusual encryption salt parameters
3. Track LibreOffice version inventory across enterprise
4. Monitor for unexpected child processes spawned from LibreOffice
5. Log all OOXML document access attempts with source/destination tracking
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع الأنظمة التي تقوم بتشغيل إصدارات LibreOffice 26.2.0-26.2.2 و25.8.0-25.8.6
2. تقييد معالجة المستندات من مصادر غير موثوقة حتى اكتمال التصحيح
3. تعطيل فتح المستندات التلقائي في عملاء البريد الإلكتروني
4. تنفيذ تقسيم الشبكة للأنظمة التي تعالج مستندات OOXML

إرشادات التصحيح:
1. ترقية LibreOffice إلى الإصدار 26.2.3 أو أحدث لفرع 26.2.x
2. ترقية LibreOffice إلى الإصدار 25.8.7 أو أحدث لفرع 25.8.x
3. اختبار التصحيحات في بيئة غير الإنتاج قبل النشر
4. إعطاء الأولوية لتصحيح الأنظمة التي تتعامل مع المستندات الحكومية/المالية

الضوابط البديلة (إذا تأخر التصحيح):
1. تنفيذ قائمة بيضاء للتطبيقات لتنفيذ LibreOffice
2. تشغيل LibreOffice في بيئات معزولة باستخدام الحاويات أو المحاكاة الافتراضية
3. تعطيل فتح مستندات OOXML عبر إعدادات أمان الماكرو
4. استخدام أدوات تحويل المستندات مع التحقق الصارم من المدخلات
5. مراقبة أنماط الوصول إلى الملفات لمعالجة OOXML المريبة

قواعد الكشف:
1. مراقبة أعطال عملية LibreOffice عند معالجة ملفات OOXML
2. التنبيه على ملفات OOXML ذات معاملات ملح تشفير غير عادية
3. تتبع جرد إصدار LibreOffice عبر المؤسسة
4. مراقبة العمليات الفرعية غير المتوقعة التي تم إطلاقها من LibreOffice
5. تسجيل جميع محاولات الوصول إلى مستندات OOXML مع تتبع المصدر/الوجهة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy A.12.2.1 - Monitoring of system use
🔵 SAMA CSF
ID.RA-1 - Asset management and vulnerability identification PR.IP-12 - Software development and acquisition security DE.CM-8 - Vulnerability scans
🟡 ISO 27001:2022
A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy A.12.2.1 - Monitoring of system use A.12.3.1 - Event logging
🟣 PCI DSS v4.0.1
6.2 - Security patches and updates 6.5.1 - Injection flaws 11.2 - Vulnerability scanning
📦 Affected Products / CPE 2 entries
libreoffice:libreoffice
libreoffice:libreoffice
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-787
EPSS0.02%
Exploit No
Patch ✗ No
Published 2026-05-07
Source Feed nvd
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-787
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.