Critical Remote Code Execution in OriginLab OriginPro (CVE‑2026‑18289) Enables Arbitrary Code Execution via Malicious OPJ Files
What It Is — OriginLab’s data‑analysis suite OriginPro contains an out‑of‑bounds write in its OPJ file parser. A crafted OPJ file can cause the application to write past allocated memory, allowing an attacker to run arbitrary code in the context of the current process.
Exploitability — Remote code execution is possible, but user interaction is required (the victim must open a malicious OPJ file or visit a page that triggers the download). CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploits are known yet, but the vendor has released a patch.
Affected Products — OriginLab OriginPro (all versions prior to the August 2026 security update).
Why It Matters for Compliance & Audit Readiness
- Control Mapping – The flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of timely patching is a core audit artifact.
- Continuous Evidence – Demonstrating that all endpoint applications are patched and that file‑parsing controls are validated satisfies the “monitoring of security controls” requirement in the Trust Services Criteria.
- Due Diligence – Enterprise buyers increasingly request proof that SaaS tools undergo regular vulnerability assessments and that remediation is tracked in a centralized compliance platform.
Recommended Actions
- Deploy OriginLab’s August 2026 patch to all OriginPro installations immediately.
- Verify the installed version against the vendor’s advisory and update your asset inventory.
- Incorporate patch‑status checks into your continuous compliance monitoring solution to generate audit‑ready evidence.
- Conduct a focused test of file‑parsing controls (e.g., sandboxed opening of OPJ files) to confirm the vulnerability is mitigated.
Source: Zero Day Initiative advisory – ZDI‑26‑548 (CVE‑2026‑18289)