ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI advisory ZDI-26-548 discloses CVE-2026-18289, an out-of-bounds write in OriginLab OriginPro OPJ parsing enabling remote code execution via malicious files.
OriginLab OriginPro contains an out-of-bounds write when parsing OPJ project files, tracked as CVE-2026-18289 with CVSS 7.8. Remote code execution requires user interaction, meaning the target must open a malicious file or visit a malicious page. The flaw was disclosed through ZDI advisory ZDI-26-548.
- Out-of-bounds write in OPJ file parsing, CVE-2026-18289, CVSS 7.8
- RCE requires user to open malicious file or visit malicious page
- Affects niche scientific software OriginLab OriginPro
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18289 | Out-of-Bounds Write RCE in OriginLab OriginPro OPJ File Parsing OriginLab OriginPro contains an out-of-bounds write vulnerability (CWE-787) in its parsing of OPJ project files, where insufficient validation of user-supplied data allows a write past the end of an allocated data structure. Exploitation requires user interaction: the target must open a malicious OPJ file or visit a page that delivers one. A successful attack lets the attacker execute arbitrary code in the context of the current process, i.e., with the privileges of the logged-in user running OriginPro (CVSS 3.0 score 7.8 High). Any user of affected OriginLab OriginPro builds is exposed whenever the application parses an attacker-supplied OPJ file. The flaw was disclosed via Trend Micro ZDI (ZDI-CAN-29332, ZDI-26-548); there is no public proof-of-concept, EPSS is 0.2%, and it is not in CISA KEV, so no exploitation is currently known. Do: Update OriginPro to the patched build referenced in ZDI-26-548 / OriginLab's advisory, as no fixed version number is included in this data. Until patched, do not open OPJ files from untrusted sources and caution users who routinely exchange Origin project files by email or download. With no public PoC, EPSS at 0.2%, and no KEV listing, exploitation risk is currently low but typical of file-parsing bugs that attackers favor for spear-phishing lures. | 7.8 | <1% |
| nichelikely tens of thousands of seats worldwide (specialized scientific desktop application) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18289.
This source does not provide full text. Read it at zerodayinitiative.com.