CVE-2026-19886

Security Advisory: CVE-2026-19886

Title: Origin Viewer OGM File Parsing Memory Corruption Vulnerability

CVE: CVE-2026-19886

ZDI Reference: ZDI-CAN-29340

Severity: High

CVSS Score: 7.8

CVSS Vector: AV/AC/PR/UI/S/C/I/A

Summary:

A vulnerability was identified in OriginLab Origin Viewer involving the parsing of specially crafted OGM files.

An attacker could exploit this vulnerability by convincing a user to open a malicious OGM file in Origin Viewer. Improper handling of data while parsing the file could result in memory corruption, potentially allowing arbitrary code execution in the context of the affected application.

User interaction is required to exploit this vulnerability.

Affected Product:

Origin Viewer

The vulnerability was reported against Origin Viewer version 9.9.5.63.

Impact:

Successful exploitation could allow an attacker to execute arbitrary code with the privileges of the user running Origin Viewer.

Resolution:

OriginLab has corrected this vulnerability in Origin Viewer 10.4.0. Users of earlier versions of Origin Viewer should update to Origin Viewer 10.4.0 or later, available from the OriginLab website at OriginLab.com or https://www.originlab.com/viewer/index.aspx.

Acknowledgment:

OriginLab thanks rgod, working with TrendAI Zero Day Initiative, and Trend Micro’s Zero Day Initiative for responsibly reporting this vulnerability.