Security Advisory: CVE-2026-19886
Title: Origin Viewer OGM File Parsing Memory Corruption Vulnerability
CVE: CVE-2026-19886
ZDI Reference: ZDI-CAN-29340
Severity: High
CVSS Score: 7.8
CVSS Vector: AV/AC/PR/UI/S/C/I/A
Summary:
A vulnerability was identified in OriginLab Origin Viewer involving the parsing of specially crafted OGM files.
An attacker could exploit this vulnerability by convincing a user to open a malicious OGM file in Origin Viewer. Improper handling of data while parsing the file could result in memory corruption, potentially allowing arbitrary code execution in the context of the affected application.
User interaction is required to exploit this vulnerability.
Affected Product:
Origin Viewer
The vulnerability was reported against Origin Viewer version 9.9.5.63.
Impact:
Successful exploitation could allow an attacker to execute arbitrary code with the privileges of the user running Origin Viewer.
Resolution:
OriginLab has corrected this vulnerability in Origin Viewer 10.4.0. Users of earlier versions of Origin Viewer should update to Origin Viewer 10.4.0 or later, available from the OriginLab website at OriginLab.com or https://www.originlab.com/viewer/index.aspx.
Acknowledgment:
OriginLab thanks rgod, working with TrendAI Zero Day Initiative, and Trend Micro’s Zero Day Initiative for responsibly reporting this vulnerability.