Junglewise Threat Intelligence

CVE-2026-19886: OriginLab Origin Viewer memory corruption in OGM file parsing

CVE-2026-19886 · Severity: high · CVSS 7.8 · Published 2026-09-15

Executive brief

OriginLab Origin Viewer is a document viewer used to display scientific data and analysis files. A flaw in how it parses OGM files can cause memory corruption, allowing an attacker to execute arbitrary code on a user's computer if they are tricked into opening a malicious file or visiting a malicious webpage. This could lead to complete system compromise.

Technical details

This vulnerability is a memory corruption flaw (CWE-119) resulting from insufficient validation of user-supplied data in the OGM file parser within OriginLab Origin Viewer. The attack vector is local with user interaction required—the target must open a malicious OGM file or visit a webpage hosting one. No authentication or elevated privileges are needed. An attacker can exploit this to achieve arbitrary code execution in the context of the Origin Viewer process. The vulnerability has been fixed in Origin Viewer version 10.4.0.25 and later.

Affected products

  • OriginLab Origin Viewer

Timeline

  • 2026-04-09: disclosed: Vulnerability reported to vendor
  • 2026-08-24: patched: Fixed in Origin Viewer 10.4.0.25
  • 2026-08-24: advisory: Coordinated public release of advisory

References

Related threats