Security Advisory: CVE-2026-18291
Title: OriginPro OGW File Parsing Memory Corruption Vulnerability
Severity: High (CVSS 7.8)
Affected Products
Origin 2026b SR0 and earlier
Fixed In
Origin 2026b SR1
Description
A vulnerability in Origin’s processing of OGW project files could result in memory corruption when opening a specially crafted file. If successfully exploited, the vulnerability could allow arbitrary code execution in the context of the current user.
Impact
An attacker could persuade a user to open a malicious OGW file, potentially resulting in arbitrary code execution.
Mitigation
Customers should update to Origin 2026b SR1 or later.
As a general security practice, users should avoid opening project files obtained from untrusted sources.
Credits
OriginLab thanks Trend Micro Zero Day Initiative and the researcher rgod for responsibly reporting this vulnerability.
References
CVE-2026-18291 ZDI-CAN-29334