ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-552: OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

mediumVulnerabilityimportance 20CVE-2026-18293
AI summary · glm-5.3

ZDI discloses CVE-2026-18293, a CVSS 7.8 out-of-bounds write in OriginLab Origin Viewer OPJ file parsing enabling remote code execution via malicious files.

ZDI advisory ZDI-26-552 describes an out-of-bounds write in OriginLab Origin Viewer's OPJ file parsing, tracked as CVE-2026-18293 with a CVSS score of 7.8. The flaw allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file.

  • CVE-2026-18293: OPJ file parsing out-of-bounds write in OriginLab Origin Viewer
  • CVSS 7.8; remote code execution possible
  • User interaction required via malicious page or file

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18293
Out-of-Bounds Write RCE in OriginLab Origin Viewer OPJ File Parsing

OriginLab Origin Viewer contains an out-of-bounds write vulnerability (CWE-787) in its parsing of OPJ project files, caused by insufficient validation of user-supplied data that allows a write past the end of an allocated structure. Exploitation requires user interaction: the target must open a maliciously crafted OPJ file (or visit a malicious page), after which the attacker can execute arbitrary code in the context of the current process. Any user of the free Origin Viewer who opens untrusted OPJ files is affected, with the highest risk in environments that routinely exchange scientific data files by email or download. As of now there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days. The issue was coordinated by Trend Micro ZDI (ZDI-CAN-29336, advisory ZDI-26-552).

Do: Check OriginLab's site or the ZDI-26-552 advisory for an updated Origin Viewer release addressing CVE-2026-18293 and update as soon as a fix is available. Until then, treat OPJ files from untrusted sources (email attachments, downloads, shared drives) as risky and open them only after confirming their origin. Because exploitation requires user interaction, reinforce guidance against opening unexpected scientific data files.

7.8<1%
  • OriginLab Origin Viewer
moderate≈10,000–100,000 desktop users (estimate)
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18293.

This source does not provide full text. Read it at zerodayinitiative.com.