ZeroHour

CVE-2026-18293

moderate

Out-of-Bounds Write RCE in OriginLab Origin Viewer OPJ File Parsing

CVSS 3.0
7.8 high
EPSS
<1%p10
Published
()
Modified
AI analysis

OriginLab Origin Viewer contains an out-of-bounds write vulnerability (CWE-787) in its parsing of OPJ project files, caused by insufficient validation of user-supplied data that allows a write past the end of an allocated structure. Exploitation requires user interaction: the target must open a maliciously crafted OPJ file (or visit a malicious page), after which the attacker can execute arbitrary code in the context of the current process. Any user of the free Origin Viewer who opens untrusted OPJ files is affected, with the highest risk in environments that routinely exchange scientific data files by email or download. As of now there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days. The issue was coordinated by Trend Micro ZDI (ZDI-CAN-29336, advisory ZDI-26-552).

What to do: Check OriginLab's site or the ZDI-26-552 advisory for an updated Origin Viewer release addressing CVE-2026-18293 and update as soon as a fix is available. Until then, treat OPJ files from untrusted sources (email attachments, downloads, shared drives) as risky and open them only after confirming their origin. Because exploitation requires user interaction, reinforce guidance against opening unexpected scientific data files.

Affected
OriginLab Origin Viewer
Estimated exposure
moderate≈10,000–100,000 desktop users (estimate) — Origin Viewer is a free desktop companion for opening OriginLab project files in the scientific/engineering community, so exposure is bounded by that user base; it is not an internet-exposed service and no public install counts or scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJ files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29336.

Weakness
CWE-787
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI discloses CVE-2026-18293, a CVSS 7.8 out-of-bounds write in OriginLab Origin Viewer OPJ file parsing enabling remote code execution via malicious files.

ZDI advisory ZDI-26-552 describes an out-of-bounds write in OriginLab Origin Viewer's OPJ file parsing, tracked as CVE-2026-18293 with a CVSS score of 7.8. The flaw allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file.

ZDI Published Advisories · Aug 11, 2026VulnerabilityCVE-2026-18293