Out-Of-Bounds Write Vulnerability in OriginLab OriginPro Product
CVE-2026-18289
7.8HIGH
What is CVE-2026-18289?
The vulnerability related to OriginLab's OriginPro arises from an improper validation in the parsing of OPJ files. This flaw enables remote attackers to execute arbitrary code by exploiting the software to write past the allocated data structure boundary. The attack vector requires user interaction, necessitating that victims visit a malicious webpage or open a specially crafted OPJ file. When exploited, this vulnerability allows attackers to run unauthorized code within the context of the current process, potentially compromising system integrity and data security.
Affected Version(s)
OriginPro 2026 SR1
