Junglewise Threat Intelligence

CVE-2026-19885: OriginLab Origin Viewer out-of-bounds write in OGWU file parsing

CVE-2026-19885 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

OriginLab Origin Viewer is a data visualization and analysis tool used to open and display scientific data files. This vulnerability allows attackers to execute arbitrary code on a user's computer by crafting a malicious OGWU data file. If a user opens the malicious file, the attacker gains full control over the affected system, potentially enabling data theft, malware installation, or further network compromise.

Technical details

The vulnerability is an out-of-bounds write flaw in the OGWU file parser of OriginLab Origin Viewer. The parser fails to properly validate user-supplied data when processing OGWU files, leading to a write past the end of an allocated buffer. An attacker can exploit this by crafting a malicious OGWU file that, when opened by a victim, triggers the buffer overflow and allows execution of arbitrary code in the context of the viewer process. The attack requires user interaction (opening a malicious file), and affects Origin Viewer versions prior to 10.4.0.25, which contains the fix.

Affected products

  • OriginLab Origin Viewer before 10.4.0.25

Timeline

  • 2026-03-31: disclosed: Vulnerability reported to vendor
  • 2026-08-24: patched: Fix released in Origin Viewer 10.4.0.25
  • 2026-08-24: advisory: Coordinated public release of advisory ZDI-26-585

References

Related threats