ZDI-26-551: OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability
ZDI advisory ZDI-26-551 discloses CVE-2026-18292, memory corruption in OriginLab OriginPro OGG file parsing enabling remote code execution with user interaction.
OriginLab OriginPro contains a memory corruption vulnerability when parsing OGG files, tracked as CVE-2026-18292 with CVSS 7.8. Remote code execution requires user interaction, meaning the target must open a malicious file or visit a malicious page. ZDI published the finding as advisory ZDI-26-551.
- Memory corruption in OGG file parsing, CVE-2026-18292, CVSS 7.8
- RCE requires user to open malicious file or visit malicious page
- Third OriginPro parsing flaw disclosed by ZDI this batch
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18292 | Memory Corruption RCE in OriginLab OriginPro OGG File Parsing OriginLab OriginPro contains a memory corruption flaw (CWE-119) in its parsing of OGG files, caused by insufficient validation of user-supplied data. An attacker exploits it by convincing a user to open a malicious OGG file (or, per the advisory, visit a malicious page), which triggers the memory corruption and allows execution of arbitrary code in the context of the current process. Any installation of OriginPro whose users open OGG data files from untrusted sources is potentially affected; the available data does not specify affected version ranges. Exploitation is not currently observed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only ~0.2% probability of exploitation within 30 days. The vulnerability was disclosed through Trend Micro ZDI (ZDI-CAN-29335, advisory ZDI-26-551). Do: Check advisory ZDI-26-551 and OriginLab's release notes for the fixed OriginPro version and upgrade promptly, as fixed-version details are not included in the available data. Until patched, do not open OGG files from untrusted sources in OriginPro and brief users who routinely exchange lab data files. No KEV listing or public PoC exists yet, so treat this as a watch-list item and re-check EPSS/KEV status for changes. | 7.8 | <1% |
| moderate≈ tens of thousands of licensed desktop users worldwide (estimate; no public install counts available) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18292.
This source does not provide full text. Read it at zerodayinitiative.com.