Junglewise Threat Intelligence

CVE-2026-18292: OriginLab OriginPro memory corruption in OGG file parsing

CVE-2026-18292 · Severity: high · CVSS 7.8 · Published 2026-08-20

Technologies: OriginLab OriginPro. Vendors: OriginLab.

Executive brief

OriginPro is a scientific data analysis and graphing tool used by researchers and engineers. A memory corruption vulnerability in its OGG file parser allows attackers to execute arbitrary code if a user opens a malicious project file, potentially compromising all data and system access of the logged-in user.

Technical details

The vulnerability exists in OriginPro's parsing of OGG project files due to insufficient validation of user-supplied data, resulting in memory corruption. An attacker can craft a specially malicious OGG file that triggers this condition, achieving arbitrary code execution in the context of the current process. Exploitation requires user interaction—the target must be tricked into opening the malicious file. The attack vector is local/user interaction (not network-reachable exploitation). OriginLab has released a patch in Origin 2026b SR1 and later versions.

Affected products

  • OriginLab OriginPro 2026b SR0 and earlier

Timeline

  • 2026-04-09: disclosed: Vulnerability reported to vendor
  • 2026-08-11: patched: Coordinated public release and patch availability (Origin 2026b SR1)
  • 2026-08-20: advisory: Public advisory published

References

Related threats