HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in OriginLab OriginPro (CVE‑2026‑18291) via OGW File Parsing

OriginLab OriginPro’s OGW file parser contains a memory‑corruption flaw (CVE‑2026‑18291) that enables remote code execution when a crafted file is opened. The issue underscores the need for robust input‑validation controls and continuous compliance evidence for SOC 2 audits.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in OriginLab OriginPro (CVE‑2026‑18291) via OGW File Parsing

What It Is — OriginLab’s OriginPro data‑analysis suite contains a memory‑corruption flaw in its OGW file parser that lets a remote attacker execute arbitrary code. Exploitation requires a victim to open a crafted OGW file or visit a malicious page that triggers the parser.

Exploitability — CVSS 7.8 (High). The vulnerability is publicly disclosed, a vendor patch is available, and proof‑of‑concept code has been shared in the advisory.

Affected Products — OriginLab OriginPro (all versions prior to the August 2026 security update).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: The flaw highlights a gap in input‑validation controls (SOC 2 CC6.1 – System Operations). Continuous mapping of such technical controls to audit criteria is essential for a defensible SOC 2 posture.
  • Evidence Collection: Demonstrating timely patch management and remediation evidence satisfies the “Change Management” and “Risk Management” criteria of SOC 2.
  • Due Diligence: Enterprises that rely on OriginPro for research data must evidence that third‑party software is regularly assessed against security baselines, a requirement increasingly scrutinized by auditors and partners.

Recommended Actions

  • Deploy OriginLab’s August 2026 patch to all OriginPro installations immediately.
  • Update your asset inventory and tag OriginPro instances for continuous vulnerability monitoring.
  • Map the input‑validation weakness to SOC 2 CC6.1 controls, capture remediation tickets as audit evidence, and verify the change in your control‑testing logs.

Source: Zero Day Initiative Advisory – ZDI‑26‑550

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-550/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →