CVE-2026-18293

Security Advisory: CVE-2026-18293

Title: Origin Viewer OPJ File Parsing Out-of-Bounds Write Vulnerability

Severity: High (CVSS 7.8)

Affected Products

Origin Viewer 9.9.5 and earlier

Fixed In

Origin Viewer 10.4.0.25 or later on our website https://www.originlab.com/viewer/

Description

A vulnerability was identified in Origin Viewer’s processing of OPJ project files. A specially crafted OPJ project file could trigger an out-of-bounds write during file parsing. If successfully exploited, the vulnerability could allow arbitrary code execution in the context of the current user.

Impact

An attacker could persuade a user to open a malicious OPJ project file in Origin Viewer, potentially allowing arbitrary code execution with the privileges of the logged-in user.

Mitigation

Users should update to the latest version of Origin Viewer on our website https://www.originlab.com/viewer/.

As a general security practice, users should avoid opening project files obtained from untrusted or unknown sources.

Credits

OriginLab thanks Trend Micro Zero Day Initiative and the researcher rgod for responsibly reporting this vulnerability.

References

CVE-2026-18293
ZDI-CAN-29336