HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in OriginLab OriginPro (CVE‑2026‑18289) Enables Arbitrary Code Execution via Malicious OPJ Files

A newly disclosed vulnerability (CVE‑2026‑18289) in OriginLab's OriginPro allows remote attackers to execute arbitrary code by tricking users into opening a crafted OPJ file. The flaw earns a CVSS 7.8 score and has been patched by the vendor. For SOC 2‑compliant organizations, this underscores the need for rigorous application control testing and documented patch management.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in OriginLab OriginPro (CVE‑2026‑18289) Enables Arbitrary Code Execution via Malicious OPJ Files

What It Is — OriginLab’s data‑analysis suite OriginPro contains an out‑of‑bounds write in its OPJ file parser. A crafted OPJ file can cause the application to write past allocated memory, allowing an attacker to run arbitrary code in the context of the current process.

Exploitability — Remote code execution is possible, but user interaction is required (the victim must open a malicious OPJ file or visit a page that triggers the download). CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploits are known yet, but the vendor has released a patch.

Affected Products — OriginLab OriginPro (all versions prior to the August 2026 security update).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The flaw maps to SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); evidence of timely patching is a core audit artifact.
  • Continuous Evidence – Demonstrating that all endpoint applications are patched and that file‑parsing controls are validated satisfies the “monitoring of security controls” requirement in the Trust Services Criteria.
  • Due Diligence – Enterprise buyers increasingly request proof that SaaS tools undergo regular vulnerability assessments and that remediation is tracked in a centralized compliance platform.

Recommended Actions

  • Deploy OriginLab’s August 2026 patch to all OriginPro installations immediately.
  • Verify the installed version against the vendor’s advisory and update your asset inventory.
  • Incorporate patch‑status checks into your continuous compliance monitoring solution to generate audit‑ready evidence.
  • Conduct a focused test of file‑parsing controls (e.g., sandboxed opening of OPJ files) to confirm the vulnerability is mitigated.

Source: Zero Day Initiative advisory – ZDI‑26‑548 (CVE‑2026‑18289)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-548/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →