ThreatCluster

Critical Vulnerability in OriginLab Origin Viewer Allows Remote Code Execution

First seen 12 Aug 2026, 08:39 UTC Zerodayinitiativedocs.originlab.comwww.cve.org 83% similarity 72

Article Content

Browse articles
ThreatCluster

A vulnerability identified as CVE-2026-18294 affects OriginLab's Origin Viewer, allowing attackers to execute arbitrary code through specially crafted OGW project files. The flaw arises from improper validation during file parsing, leading to memory corruption. Successful exploitation requires user interaction, such as opening a malicious OGW file. This vulnerability impacts all versions of Origin Viewer 10.4.0.25 and earlier. OriginLab has released an update to mitigate the issue, urging users to upgrade immediately. Users are also advised to avoid opening files from untrusted sources. The vulnerability was reported by the Trend Micro Zero Day Initiative and researcher rgod.

Key Points: • CVE-2026-18294 allows arbitrary code execution in Origin Viewer via OGW files. • User interaction is required for exploitation, making it a targeted attack vector. • OriginLab has released a patch; users should update immediately to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
CVE-2026-18294 published
OriginLab disclosed a critical vulnerability in Origin Viewer affecting versions 10.4.0.25 and earlier, allowing remote code execution.
docs.originlab.com
2026-08-12
Patch released
OriginLab issued an update to fix the vulnerability, urging users to upgrade to the latest version.
Zerodayinitiative

Community

Browse all →

Tracked Entities in This Story