Description
OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of OPJU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
. Was ZDI-CAN-29331.
Published: 2026-08-20
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

OriginLab OriginPro has a flaw in its OPJU file parsing routine that allows an out-of-bounds write, classified as CWE-787. The lack of proper validation of user-supplied data causes the application to write past the end of an allocated buffer. This overflow can be exploited to execute arbitrary code in the context of the current process, giving an attacker full control of the affected system.

Affected Systems

The vulnerability affects OriginLab OriginPro. No specific version information is available, so any installation of OriginPro that has not received the vendor’s fix is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score is not available and the issue is not listed in CISA KEV, but the vulnerability requires user interaction: the target must open a malicious OPJU file or visit a malicious page. This makes exploitation possible but not purely passive, and the ability to run arbitrary code indicates a significant risk for confidentiality, integrity, and availability if the attacker gains control of the process.

Generated by OpenCVE AI on August 20, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest OriginPro patch supplied by OriginLab to address the out-of-bounds write in OPJU parsing.
  • Temporarily block or quarantine OPJU file handling to prevent exploitation until the patch is applied.
  • Monitor system logs for attempts to open or parse OPJU files and report any suspicious activity.

Generated by OpenCVE AI on August 20, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Originlab
Originlab originpro
Vendors & Products Originlab
Originlab originpro

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OPJU files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process. . Was ZDI-CAN-29331.
Title OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Weaknesses CWE-787
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Originlab Originpro
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-09-02T03:55:22.864Z

Reserved: 2026-07-29T17:08:30.843Z

Link: CVE-2026-18288

cve-icon Vulnrichment

Updated: 2026-08-21T20:06:57.217Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-20T17:17:25.397

Modified: 2026-09-02T04:17:47.247

Link: CVE-2026-18288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:05Z

Weaknesses