CVE-2026-19885

Security Advisory: CVE-2026-19885

Title: Origin Viewer OGWU File Parsing Out-of-Bounds Write Vulnerability

CVE: CVE-2026-19885

ZDI Reference: ZDI-CAN-29337

Severity: High

CVSS Score: 7.8

CVSS Vector: AV/AC/PR/UI/S/C/I/A

Summary:

A vulnerability was identified in OriginLab Origin Viewer involving the parsing of specially crafted OGWU files.

An attacker could exploit this vulnerability by convincing a user to open a malicious OGWU file in Origin Viewer. Improper validation of data while parsing the file could result in an out-of-bounds write, potentially allowing arbitrary code execution in the context of the affected application.

User interaction is required to exploit this vulnerability.

Affected Product:

Origin Viewer 9.9.5.63

The vulnerability was reported against Origin Viewer version 9.9.5.63.

Impact:

Successful exploitation could allow an attacker to execute arbitrary code with the privileges of the user running Origin Viewer.

Resolution:

OriginLab has corrected this vulnerability in Origin Viewer 10.4.0. Users of earlier versions of Origin Viewer should update to Origin Viewer 10.4.0 or later, available from the OriginLab website at OriginLab.com or https://www.originlab.com/viewer/index.aspx.

Acknowledgment:

OriginLab thanks rgod, working with TrendAI Zero Day Initiative, and Trend Micro’s Zero Day Initiative for responsibly reporting this vulnerability.