CVE-2026-79592
Received Received - Intake

Out-of-Bounds Read in libxls via OLE Summary Offsets

Vulnerability report for CVE-2026-79592, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: MITRE

Description

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
libxls libxls 1.6.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in the xls_dumpSummary() function of libxls version 1.6.3. It occurs because the function does not properly validate OLE summary offsets controlled by the file, which can lead to reading memory outside the intended buffer.

Impact Analysis

An attacker could exploit this to read sensitive data from memory, crash the application, or potentially execute arbitrary code if combined with other vulnerabilities. This may affect applications using libxls to process untrusted XLS files.

Mitigation Strategies

Update libxls to the latest version beyond 1.6.3 to address the out-of-bounds read vulnerability in xls_dumpSummary().

Avoid opening untrusted Excel files, as they may trigger the vulnerability through malformed OLE summary offsets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79592. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart