Security Advisory: CVE-2026-18294
Title: Origin Viewer OGW Project File Parsing Memory Corruption Vulnerability
Severity: High (CVSS 7.8)
Affected Products
Origin Viewer 9.9.5 and earlier
Fixed In
Origin Viewer 10.4.0.25 or later on our website https://www.originlab.com/viewer/
Description
A vulnerability was identified in Origin Viewer’s processing of OGW project files. A specially crafted OGW project file could trigger memory corruption during file parsing. If successfully exploited, the vulnerability could allow arbitrary code execution in the context of the current user.
Impact
An attacker could persuade a user to open a malicious OGW project file in Origin Viewer, potentially allowing arbitrary code execution with the privileges of the logged-in user.
Mitigation
Users should update to the latest version of Origin Viewer on our website https://www.originlab.com/viewer/
As a general security practice, users should avoid opening project files obtained from untrusted or unknown sources.
Credits
OriginLab thanks Trend Micro Zero Day Initiative and the researcher rgod for responsibly reporting this vulnerability.
References
CVE-2026-18294
ZDI-CAN-29338