ZeroHour

CVE-2026-18291

moderate

Memory Corruption RCE in OriginLab OriginPro OGW File Parsing

CVSS 3.0
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-18291 is a memory corruption vulnerability (CWE-119) in the way OriginLab OriginPro parses OGW project files: user-supplied data is not properly validated, corrupting memory during parsing. Exploitation requires user interaction, as the target must open a malicious OGW file (or, per the advisory, visit a malicious page), meaning an attacker would need to deliver a crafted file via email, download, or a shared repository. If successful, the attacker executes arbitrary code in the context of the current process, gaining the privileges of the user running OriginPro on that workstation. All OriginPro users who open OGW files from untrusted sources are affected, although the disclosure does not state which specific versions are vulnerable. The flaw was disclosed through Trend Micro ZDI (ZDI-CAN-29334 / ZDI-26-550) and there are no signs of exploitation so far: no public PoC, not listed in CISA KEV, and EPSS puts the 30-day exploitation probability at only 0.2%.

What to do: Watch OriginLab's advisory tied to ZDI-26-550 and install the patched OriginPro build as soon as it is identified, since fixed version numbers are not named in this disclosure. Until then, avoid opening OGW and other Origin project files from untrusted email attachments, downloads, or shared locations, and consider opening untrusted files on an isolated or non-privileged workstation. Because exploitation depends on user interaction, awareness training around malicious Origin project files is the key interim mitigation.

Affected
OriginLab OriginPro
Estimated exposure
moderateplausibly on the order of tens of thousands of licensed seats worldwide (no public install counts available) — OriginPro is a specialized Windows desktop application for scientific graphing and data analysis licensed primarily to individual researchers, university labs, and industry R&D groups, and exposure is limited to workstations whose users…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGW files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29334.

Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-550: OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI discloses a memory corruption flaw in OriginLab OriginPro OGW file parsing enabling remote code execution via malicious files (CVE-2026-18291, CVSS 7.8).

ZDI advisory ZDI-26-550 describes a memory corruption vulnerability in OriginLab OriginPro OGW file parsing that allows remote attackers to execute arbitrary code. User interaction is required: the target must visit a malicious page or open a malicious file. The flaw has a CVSS rating of 7.8 and is assigned CVE-2026-18291.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-18291