ZeroHour

CVE-2026-18288

moderate

Out-of-Bounds Write RCE in OriginLab OriginPro OPJU File Parsing

CVSS 3.0
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-18288 is an out-of-bounds write vulnerability (CWE-787) in the OPJU file parser of OriginLab OriginPro, disclosed by Trend Micro's Zero Day Initiative as ZDI-26-547 (ZDI-CAN-29331). The flaw stems from a lack of proper validation of user-supplied data during parsing, which allows a write past the end of an allocated data structure. An attacker triggers it by persuading the victim to open a maliciously crafted OPJU file or visit a malicious page; user interaction is required, and successful exploitation yields arbitrary code execution in the context of the current process. Any user of an affected OriginPro installation who opens untrusted OPJU project files is exposed, most commonly researchers and lab staff in academic, government, and industry settings, and the disclosure does not specify affected version ranges. There are no public proof-of-concept exploits, no CISA KEV listing, and EPSS puts the 30-day exploitation probability at 0.2% (about the 10th percentile), indicating no known exploitation at this time.

What to do: Apply the OriginLab update referenced in advisory ZDI-26-547 once OriginLab publishes fixed versions, and inventory endpoints running OriginPro to prioritize patching. Until patched, avoid opening OPJU project files from untrusted sources and exercise caution with unsolicited email attachments and links to malicious pages.

Affected
OriginLab OriginPro
Estimated exposure
moderatelikely tens of thousands of desktop installations (estimate) — OriginPro is a specialized, per-seat desktop scientific graphing application used mainly in academic, government, and industry research labs; it is not typically internet-exposed and the provided data contains no installation counts, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-29331.

Weakness
CWE-787
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI advisory ZDI-26-547 discloses CVE-2026-18288, an out-of-bounds write in OriginLab OriginPro OPJU file parsing enabling remote code execution via crafted files.

OriginLab OriginPro contains an out-of-bounds write when parsing OPJU files, tracked as CVE-2026-18288 with CVSS 7.8. Remote code execution requires user interaction, meaning the target must open a malicious file or visit a malicious page. The flaw was disclosed via ZDI advisory ZDI-26-547.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-18288