ZeroHour

CVE-2026-19886

niche

Memory Corruption RCE in OriginLab Origin Viewer via Malicious OGM Files

CVSS 3.0
7.8 high
EPSS
Published
()
Modified
AI analysis

A memory corruption vulnerability (CWE-119) in OriginLab Origin Viewer allows remote attackers to execute arbitrary code in the context of the current process when a victim opens a malicious OGM file or visits a malicious web page. The flaw stems from improper validation of user-supplied data during OGM file parsing, which can corrupt memory and lead to full compromise of the affected workstation. Because the attack vector is local (AV:L) and requires user interaction (UI:R), exploitation depends on socially engineering a target into opening a weaponized file, a pattern well suited to spearphishing campaigns against research and academic users. Affected users are those running OriginLab Origin Viewer, a free desktop utility used to inspect Origin project and graph files common in scientific data analysis. No public proof of concept is known and the vulnerability is not listed in CISA's KEV catalog.

What to do: Do not open OGM (or other Origin) files received from untrusted sources or follow links that auto-open such files, since exploitation requires user interaction. Check the ZDI-26-586 advisory and OriginLab's site for a patched version and upgrade the Viewer as soon as a fix ships. As defense-in-depth, run Origin Viewer under a non-administrator account and consider blocking or sandboxing OGM file types at the email gateway.

Affected
OriginLab Origin Viewer
Estimated exposure
nicheLikely tens of thousands of desktop users worldwide (free scientific viewer; no public install counts) — Origin Viewer is a free desktop utility for a niche scientific software ecosystem (Origin/OriginPro used across universities and research labs), with no public install counts or internet-exposed device footprint to draw from, so this is a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGM files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29340.

Weakness
CWE-119
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

ZDI-26-586: OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability

ZDI advisory ZDI-26-586 reports a memory corruption RCE (CVE-2026-19886, CVSS 7.8) in OriginLab Origin Viewer OGM file parsing, needing user interaction.

The Zero Day Initiative published advisory ZDI-26-586 describing a memory corruption vulnerability in OriginLab Origin Viewer's OGM file parsing. Exploitation allows remote code execution when a user opens a malicious file or visits a crafted page. ZDI rated the issue CVSS 7.8 and assigned CVE-2026-19886.