ZeroHour

CVE-2026-18292

moderate

Memory Corruption RCE in OriginLab OriginPro OGG File Parsing

CVSS 3.0
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

OriginLab OriginPro contains a memory corruption flaw (CWE-119) in its parsing of OGG files, caused by insufficient validation of user-supplied data. An attacker exploits it by convincing a user to open a malicious OGG file (or, per the advisory, visit a malicious page), which triggers the memory corruption and allows execution of arbitrary code in the context of the current process. Any installation of OriginPro whose users open OGG data files from untrusted sources is potentially affected; the available data does not specify affected version ranges. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only ~0.2% probability of exploitation within 30 days. The vulnerability was disclosed through Trend Micro ZDI (ZDI-CAN-29335, advisory ZDI-26-551).

What to do: Check advisory ZDI-26-551 and OriginLab's release notes for the fixed OriginPro version and upgrade promptly, as fixed-version details are not included in the available data. Until patched, do not open OGG files from untrusted sources in OriginPro and brief users who routinely exchange lab data files. No KEV listing or public PoC exists yet, so treat this as a watch-list item and re-check EPSS/KEV status for changes.

Affected
OriginLab OriginPro
Estimated exposure
moderate≈ tens of thousands of licensed desktop users worldwide (estimate; no public install counts available) — OriginPro is niche, seat-licensed desktop scientific graphing software deployed mainly in academic and industrial research labs, so the affected population is estimated from typical deployment patterns of comparable scientific packages…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGG files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29335.

Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI advisory ZDI-26-551 discloses CVE-2026-18292, memory corruption in OriginLab OriginPro OGG file parsing enabling remote code execution with user interaction.

OriginLab OriginPro contains a memory corruption vulnerability when parsing OGG files, tracked as CVE-2026-18292 with CVSS 7.8. Remote code execution requires user interaction, meaning the target must open a malicious file or visit a malicious page. ZDI published the finding as advisory ZDI-26-551.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-18292