Executive brief
OriginPro is a data analysis and graphing application used by researchers and engineers. A vulnerability in how OriginPro processes OGW project files can cause memory corruption and allow attackers to execute arbitrary code if a user opens a malicious file. An attacker could exploit this to gain full control of the user's system and access sensitive data.
Technical details
This vulnerability is a memory corruption issue (buffer overflow or similar heap corruption) in the OGW file parsing code within OriginPro. The root cause is insufficient validation of user-supplied data within specially crafted OGW files. Attack vector is local (file-based), requiring user interaction—the target must open a malicious OGW file. An attacker can leverage the memory corruption to achieve arbitrary code execution in the context of the current process. The vulnerability affects OriginPro up to version 2026b SR0; a patch is available in 2026b SR1.
Affected products
- OriginLab OriginPro 2026b SR0 and earlier
Timeline
- 2026-03-25: disclosed: Vulnerability reported to vendor
- 2026-08-11: advisory: Coordinated public disclosure via ZDI
- 2026-08-20: patched: Patch available in OriginPro 2026b SR1