CVE-2026-18288

Security Advisory: CVE-2026-18288

Title: OriginPro OPJU File Parsing Out-of-Bounds Write Vulnerability

Severity: High (CVSS 7.8)

Affected Products

Origin 2026b SR0 and earlier

Fixed In

Origin 2026b SR1

Description

A vulnerability was identified in Origin’s processing of OPJU project files. A specially crafted OPJU project file could trigger an out-of-bounds write during file parsing, resulting in heap corruption. If successfully exploited, the vulnerability could allow arbitrary code execution in the context of the current user.

Impact

An attacker could persuade a user to open a malicious OPJU project file, potentially allowing arbitrary code execution with the privileges of the logged-in user.

Mitigation

Customers should update to Origin 2026b SR1 or later.

As a general security practice, users should avoid opening project files obtained from untrusted or unknown sources.

Credits

OriginLab thanks Trend Micro Zero Day Initiative and the researcher rgod for responsibly reporting this vulnerability.

References

CVE-2026-18288
ZDI-CAN-29331