Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise interact with documents. LibreOffice internally makes use of "curl" to fetch remote resources such as images hosted on webservers. In affected versions of LibreOffice, when used in LibreOfficeKit mode only, then curl's TLS certification verification was disabled (CURLOPT_SSL_VERIFYPEER of false) In the fixed versions curl operates in LibreOfficeKit mode the same as in standard mode with CURLOPT_SSL_VERIFYPEER of true. This issue affects LibreOffice before version 24.2.4.
Conclusion & alert: CVE-2024-5261 is rated Moderate Risk (51.8/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.43%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.53% | 0.43% | -0.10% |
| 2 | 2026-03-22 | 0.56% | 0.53% | -0.03% |
| 3 | 2025-12-24 | — | 0.56% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 4.0 | CRITICAL |
|
— | — | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-5261: 1 source package rows (libreoffice); 23 state rows across 3 repos (3.20-community, 3.22-community, edge-community); fixed 0, open 23. | https://security.alpinelinux.org/vuln/CVE-2024-5261 |
debian
|
unimportant | CVE-2024-5261 unimportant priority: Debian including 1 source packages (libreoffice), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2024-5261 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2024-5261/ |
ubuntu
|
medium | CVE-2024-5261 medium priority: Ubuntu including 1 source packages (libreoffice), 5 status rows across 5 suites (focal, jammy, mantic, noble, upstream): released 3, not-affected 2. | https://ubuntu.com/security/CVE-2024-5261 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libreoffice | libreoffice | < 24.2.4 | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.libreoffice.org/about-us/security/advisories/cve-2024-5261 | Vendor Advisory |