ZDI-26-549: OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18290.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate CVE-2026-18290 (ZDI-26-549) by preventing users from opening untrusted/malicious files or visiting untrusted pages that could trigger the OriginLab OriginPro OGG parsing out-of-bounds write leading to remote code execution.
Event History
Frequently Asked Questions
What is the severity of ZDI-26-549?
The severity of ZDI-26-549 is rated at 7.8 on the CVSS scale, indicating a high-risk vulnerability.
How do I fix ZDI-26-549?
To fix ZDI-26-549, update to the latest version of OriginLab OriginPro where the vulnerability has been patched.
What kind of attack is associated with ZDI-26-549?
ZDI-26-549 is associated with remote code execution attacks, where an attacker can execute arbitrary code on vulnerable systems.
What is required for an attacker to exploit ZDI-26-549?
User interaction is required to exploit ZDI-26-549, as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-26-549?
ZDI-26-549 affects installations of OriginLab OriginPro.