Memory Corruption Vulnerability in OriginLab OriginPro OGG File Parsing
CVE-2026-18292

7.8HIGH

Key Information:

Vendor

Originlab

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18292?

A memory corruption vulnerability in OriginLab OriginPro's OGG file parsing allows remote attackers to execute arbitrary code. This flaw arises from insufficient validation of user-supplied data during the parsing process. To exploit this vulnerability, a user must either visit a malicious webpage or open a compromised file, leading to potential execution of unauthorized commands in the context of the current process. It is imperative for users to remain vigilant and update their software to mitigate the associated risks.

Affected Version(s)

OriginPro 2026 SR1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.