Junglewise Threat Intelligence

CVE-2026-18294: OriginLab Origin Viewer memory corruption in OGW file parsing

CVE-2026-18294 · Severity: high · CVSS 7.8 · Published 2026-08-20

Executive brief

OriginLab Origin Viewer is a document viewing tool used to open scientific data files. A flaw in how it parses OGW project files can cause a crash or allow arbitrary code execution if a user opens a malicious file. An attacker can exploit this by tricking a user into opening a crafted OGW file, potentially gaining full control of the victim's account and system.

Technical details

The vulnerability is a memory corruption flaw in OriginLab Origin Viewer's OGW project file parser. The parser fails to properly validate user-supplied data in crafted OGW files, leading to out-of-bounds memory access or heap corruption. Exploitation requires local attack vector (file access) and user interaction—the victim must open a malicious OGW file in Origin Viewer. Successful exploitation results in arbitrary code execution with the privileges of the current user. A patch is available in Origin Viewer version 10.4.0.25 or later.

Affected products

  • OriginLab Origin Viewer 9.9.5 and earlier

Timeline

  • 2026-04-08: disclosed: Vulnerability reported to vendor
  • 2026-08-11: advisory: Coordinated public release of advisory (ZDI-26-553)
  • 2026-08-20: patched: Fix available in Origin Viewer 10.4.0.25 or later

References

Related threats