OriginLab OriginPro Vulnerable to Remote Code Execution via OPJ File Parsing Flaw
A critical remote code execution vulnerability exists in OriginLab OriginPro due to an out-of-bounds write during OPJ file parsing, with a CVSS score of 7.8.

A critical remote code execution vulnerability has been identified in OriginLab's OriginPro scientific graphing and data analysis software. The flaw, tracked as CVE-2026-18289, stems from an out-of-bounds write error that occurs when the software parses specially crafted OPJ files. This vulnerability carries a CVSS score of 7.8, indicating a high severity.
The vulnerability allows attackers to execute arbitrary code on a victim's system. Exploitation requires user interaction, meaning an attacker must trick a user into opening a malicious OPJ file or visiting a webpage that hosts such a file. Once a user interacts with the malicious content, the out-of-bounds write can be triggered, potentially leading to the execution of attacker-controlled code within the context of the OriginPro application.
This type of vulnerability, where improper handling of file parsing leads to memory corruption and subsequent code execution, is a common attack vector. Attackers often craft malicious files that, when opened by unsuspecting users, exploit these weaknesses to gain a foothold on a system. The requirement for user interaction, while a mitigating factor, does not significantly reduce the overall risk, as social engineering tactics remain highly effective.
OriginLab has acknowledged the vulnerability and has released an update to address it. Users of OriginPro are strongly advised to apply the patch as soon as possible to mitigate the risk of exploitation. Further details regarding the patch and the specific CVE can be found on OriginLab's official documentation site.
The disclosure timeline indicates that the vulnerability was reported to the vendor on March 11, 2026, and the coordinated public release of the advisory occurred on August 11, 2026. This six-month period allowed OriginLab sufficient time to develop and distribute a fix before the vulnerability became widely known.
This advisory was published by the Zero Day Initiative (ZDI), a program that buys and responsibly discloses security vulnerabilities. The vulnerability was discovered by researcher rgod, who is credited with finding the flaw. ZDI's involvement ensures that vendors are given a chance to fix issues before they are exploited in the wild.
The potential impact of this vulnerability is significant for users who rely on OriginPro for scientific research and data analysis. Successful exploitation could lead to the compromise of sensitive research data, intellectual property theft, or the use of the affected machine as a pivot point for further network intrusion. Organizations using OriginPro should prioritize patching to protect their systems and data integrity.
This new advisory, ZDI-26-551, details a remote code execution vulnerability in OriginLab OriginPro stemming from improper parsing of OGG files, distinct from the previously reported OPJ file parsing flaw. The vulnerability allows attackers to execute arbitrary code in the context of the current process by tricking a user into opening a malicious OGG file or visiting a malicious webpage, carrying a CVSS score of 7.8.
This advisory details a remote code execution vulnerability in OriginLab OriginPro, specifically ZDI-26-549, stemming from an out-of-bounds write during the parsing of OGG files. While the previous report focused on OPJ file parsing, this new vulnerability affects a different file format, though it also carries a CVSS score of 7.8 and requires user interaction for exploitation. OriginLab has released a patch for this specific OGG file parsing flaw.
The Zero Day Initiative advisory ZDI-26-547 details a remote code execution vulnerability in OriginLab OriginPro, specifically affecting the parsing of OPJU files. This new advisory assigns CVE-2026-18288 to the flaw, which is distinct from the previously reported OPJ file parsing flaw (CVE-2026-18288). The CVSS score remains 7.8, and exploitation still requires user interaction, such as opening a malicious file.