ZDI-CAN-29332: ZDI-26-548: OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18289.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29332?
ZDI-CAN-29332 has a CVSS rating of 7.8, indicating a high-severity vulnerability.
How do I fix ZDI-CAN-29332?
To mitigate ZDI-CAN-29332, ensure that you apply the latest security updates provided by OriginLab for OriginPro.
What type of vulnerability is ZDI-CAN-29332?
ZDI-CAN-29332 is an out-of-bounds write vulnerability that can lead to remote code execution.
Is user interaction required to exploit ZDI-CAN-29332?
Yes, user interaction is required for ZDI-CAN-29332, as the victim must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-29332?
ZDI-CAN-29332 affects OriginLab OriginPro installations.