Description
OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of OGW files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29334.
Published: 2026-08-20
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The OriginPro OGW file parsing vulnerability allows an attacker that can trick a user into opening a malicious OGW file or visiting a malicious web page to overwrite heap memory and execute arbitrary code in the context of the OriginPro process. The flaw arises from missing validation when processing OGW data, resulting in a buffer overflow. Successful exploitation would give an attacker the same privileges as the user running the application, enabling remote code execution.

Affected Systems

OriginLab OriginPro installations are affected; the specific product version affected is not publicly disclosed in the advisory. All users running any unpatched version of OriginPro that still includes the OGW parser should assume vulnerability until a patch is applied.

Risk and Exploitability

The advisory lists a CVSS score of 7.8, indicating high severity, while the EPSS score is not provided and the vulnerability is not yet in the CISA KEV catalog. Because the attack requires the target to open a malicious file or access a malicious page, user interaction is required. Nevertheless, once the user engages with the malicious content, the attacker can achieve full code execution locally with the application's privileges. Given the lack of an EPSS estimate, the risk of exploitation remains uncertain but potentially significant due to the high CVSS rating.

Generated by OpenCVE AI on August 20, 2026 at 20:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update or patch for OriginLab OriginPro that addresses the OGW parsing buffer overflow.
  • Do not open or download OGW files from untrusted sources, and be cautious when visiting unfamiliar web pages that may serve malicious OGW payloads.
  • Configure application whitelisting or endpoint protection to block unauthorized execution of the OriginPro application from untrusted input.

Generated by OpenCVE AI on August 20, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OGW files. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29334.
Title OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability
Weaknesses CWE-119
References
Metrics cvssV3_0

{'score': 7.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:21:18.223Z

Reserved: 2026-07-29T17:09:04.337Z

Link: CVE-2026-18291

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:25.767

Modified: 2026-08-20T17:17:25.767

Link: CVE-2026-18291

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:30:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer