ZDI-26-547: OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI advisory ZDI-26-547 discloses CVE-2026-18288, an out-of-bounds write in OriginLab OriginPro OPJU file parsing enabling remote code execution via crafted files.
OriginLab OriginPro contains an out-of-bounds write when parsing OPJU files, tracked as CVE-2026-18288 with CVSS 7.8. Remote code execution requires user interaction, meaning the target must open a malicious file or visit a malicious page. The flaw was disclosed via ZDI advisory ZDI-26-547.
- Out-of-bounds write in OPJU file parsing, CVE-2026-18288, CVSS 7.8
- RCE requires user to open malicious file or visit malicious page
- One of several OriginPro parsing vulnerabilities disclosed by ZDI
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18288 | Out-of-Bounds Write RCE in OriginLab OriginPro OPJU File Parsing CVE-2026-18288 is an out-of-bounds write vulnerability (CWE-787) in the OPJU file parser of OriginLab OriginPro, disclosed by Trend Micro's Zero Day Initiative as ZDI-26-547 (ZDI-CAN-29331). The flaw stems from a lack of proper validation of user-supplied data during parsing, which allows a write past the end of an allocated data structure. An attacker triggers it by persuading the victim to open a maliciously crafted OPJU file or visit a malicious page; user interaction is required, and successful exploitation yields arbitrary code execution in the context of the current process. Any user of an affected OriginPro installation who opens untrusted OPJU project files is exposed, most commonly researchers and lab staff in academic, government, and industry settings, and the disclosure does not specify affected version ranges. There are no public proof-of-concept exploits, no CISA KEV listing, and EPSS puts the 30-day exploitation probability at 0.2% (about the 10th percentile), indicating no known exploitation at this time. Do: Apply the OriginLab update referenced in advisory ZDI-26-547 once OriginLab publishes fixed versions, and inventory endpoints running OriginPro to prioritize patching. Until patched, avoid opening OPJU project files from untrusted sources and exercise caution with unsolicited email attachments and links to malicious pages. | 7.8 | <1% |
| moderatelikely tens of thousands of desktop installations (estimate) |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18288.
This source does not provide full text. Read it at zerodayinitiative.com.