Remote Code Execution Vulnerability in OriginLab OriginPro
CVE-2026-18291
7.8HIGH
What is CVE-2026-18291?
A security flaw in OriginLab OriginPro allows remote attackers to execute arbitrary code through improper validation during OGW file parsing. The vulnerability exists due to memory corruption triggered by crafted user inputs. This requires user interaction, such as visiting a malicious webpage or opening a compromised file, thereby enabling remote exploitation within the context of the affected process. For further technical details, please refer to the vendor advisory.
Affected Version(s)
OriginPro 2026 SR1
