Security Advisory: CVE-2026-18289
Title: OriginPro OPJ File Parsing Out-of-Bounds Write Vulnerability
Severity: High (CVSS 7.8)
Affected Products
Origin 2026b SR0 and earlier
Fixed In
Origin 2026b SR1
Description
A vulnerability was identified in Origin’s processing of OPJ project files. A specially crafted OPJ file could trigger an out-of-bounds write during file parsing. If successfully exploited, the vulnerability could result in arbitrary code execution in the context of the current user.
Impact
An attacker could persuade a user to open a malicious OPJ project file, potentially allowing arbitrary code execution with the privileges of the logged-in user.
Mitigation
Customers should update to Origin 2026b SR1 or later.
As a general security practice, users should avoid opening project files obtained from untrusted or unknown sources.
Credits
OriginLab thanks Trend Micro Zero Day Initiative and the researcher rgod for responsibly reporting this vulnerability.
References
CVE-2026-18289 ZDI-CAN-29332