AI analysis
CVE-2026-18291 is a memory corruption vulnerability (CWE-119) in the way OriginLab OriginPro parses OGW project files: user-supplied data is not properly validated, corrupting memory during parsing. Exploitation requires user interaction, as the target must open a malicious OGW file (or, per the advisory, visit a malicious page), meaning an attacker would need to deliver a crafted file via email, download, or a shared repository. If successful, the attacker executes arbitrary code in the context of the current process, gaining the privileges of the user running OriginPro on that workstation. All OriginPro users who open OGW files from untrusted sources are affected, although the disclosure does not state which specific versions are vulnerable. The flaw was disclosed through Trend Micro ZDI (ZDI-CAN-29334 / ZDI-26-550) and there are no signs of exploitation so far: no public PoC, not listed in CISA KEV, and EPSS puts the 30-day exploitation probability at only 0.2%.
What to do: Watch OriginLab's advisory tied to ZDI-26-550 and install the patched OriginPro build as soon as it is identified, since fixed version numbers are not named in this disclosure. Until then, avoid opening OGW and other Origin project files from untrusted email attachments, downloads, or shared locations, and consider opening untrusted files on an isolated or non-privileged workstation. Because exploitation depends on user interaction, awareness training around malicious Origin project files is the key interim mitigation.
Estimated exposure
moderateplausibly on the order of tens of thousands of licensed seats worldwide (no public install counts available) — OriginPro is a specialized Windows desktop application for scientific graphing and data analysis licensed primarily to individual researchers, university labs, and industry R&D groups, and exposure is limited to workstations whose users…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGW files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29334.