ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI discloses CVE-2026-18290, a CVSS 7.8 out-of-bounds write in OriginLab OriginPro OGG file parsing enabling remote code execution via malicious files.
The Zero Day Initiative published advisory ZDI-26-549 describing an out-of-bounds write in OriginLab OriginPro's OGG file parsing, tracked as CVE-2026-18290 with a CVSS score of 7.8. The flaw allows remote attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file.
- CVE-2026-18290: OGG file parsing out-of-bounds write in OriginLab OriginPro
- CVSS 7.8; remote code execution possible
- User interaction required: malicious page or file
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18290 | Out-of-Bounds Write RCE in OriginLab OriginPro OGG File Parsing OriginLab OriginPro is vulnerable to an out-of-bounds write (CWE-787) while parsing OGG files: user-supplied data is not properly validated, allowing a write past the end of an allocated data structure. Exploitation requires user interaction, meaning the target must visit a malicious page or open a malicious file containing a crafted OGG file. A successful attack allows a remote attacker to execute arbitrary code in the context of the current process, i.e., with the privileges of the user running OriginPro. Any user of OriginLab OriginPro who opens untrusted OGG files is affected; the flaw was reported via Trend Micro Zero Day Initiative (ZDI-CAN-29333, advisory ZDI-26-549). No public proof-of-concept, in-the-wild exploitation, or KEV listing is known, and EPSS estimates only a 0.2% chance of exploitation within 30 days. Do: Check OriginLab's advisory associated with ZDI-26-549 and apply the vendor's fixed OriginPro service release as soon as it is identified, since the disclosure does not state affected or fixed version numbers. Until patched, avoid opening OGG files from untrusted sources and scrutinize email attachments and downloads that may contain them. Because the CVSS vector (AV:L/UI:R) requires local user action, user awareness is an effective interim mitigation. | 7.8 | <1% |
| moderate≈ tens of thousands of licensed desktop seats (order of magnitude 10,000-100,000) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18290.
This source does not provide full text. Read it at zerodayinitiative.com.