Junglewise Threat Intelligence

CVE-2026-18290: OriginLab OriginPro out-of-bounds write in OGG file parsing

CVE-2026-18290 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: OriginLab OriginPro. Vendors: OriginLab.

Executive brief

OriginPro is a scientific graphing and data analysis application used by researchers and engineers. A flaw in how it processes OGG project files could allow an attacker to execute arbitrary code if a user opens a malicious file, potentially compromising sensitive research data and system access with the user's privileges.

Technical details

The vulnerability is an out-of-bounds write in OriginPro's OGG file parser, resulting from insufficient validation of user-supplied data structures. An attacker can craft a malicious OGG project file that triggers a write past the end of an allocated buffer during parsing, causing memory corruption. Exploitation requires user interaction (opening a malicious OGG file), but if successful allows arbitrary code execution in the context of the current user. The issue affects OriginPro 2026b SR0 and earlier; a patch is available in OriginPro 2026b SR1.

Affected products

  • OriginLab OriginPro 2026b SR0 and earlier

Timeline

  • 2026-04-08: disclosed: Vulnerability reported to vendor
  • 2026-08-11: advisory: Coordinated public release of advisory
  • 2026-08-11: patched: Fix available in OriginPro 2026b SR1

References

Related threats