HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Out-of-Bounds Write RCE in OriginLab Origin Viewer (CVE-2026-18293) Threatens Scientific Data Tools

A CVE‑2026‑18293 vulnerability in OriginLab’s Origin Viewer allows remote attackers to execute arbitrary code via a crafted OPJ file. Exploitation requires a user to open the malicious file, but successful compromise can lead to full system takeover. For SOC 2‑compliant organizations, the incident highlights the need for rigorous third‑party patch management and auditable evidence of remediation.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Out‑of‑Bounds Write RCE in OriginLab Origin Viewer (CVE‑2026‑18293)

What It Is — OriginLab’s Origin Viewer contains an out‑of‑bounds write in its OPJ file parser that can be triggered by a crafted OPJ file. The flaw allows an attacker to execute arbitrary code in the context of the viewer process.

Exploitability — CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploit is known, but the vulnerability is exploitable when a user opens a malicious file or visits a malicious page that forces the viewer to load the file.

Affected Products — OriginLab Origin Viewer (all versions prior to the 2026‑08‑11 security update).

Why It Matters for Compliance & Audit Readiness

  • Change Management (SOC 2 CC6.1) – Demonstrating that you have a process to detect, assess, and remediate third‑party software vulnerabilities is a core audit requirement.
  • System Operations (SOC 2 CC7.1) – Evidence of timely patch deployment shows you maintain the integrity of production systems.
  • Risk Management – Unpatched scientific‑analysis tools can become an attack vector that jeopardizes data confidentiality and availability, impacting the trust you provide to research partners and funders.

Recommended Actions

  • Deploy OriginLab’s patch immediately and verify the installed version.
  • Update your asset inventory to flag all endpoints running Origin Viewer.
  • Map the vulnerability to your SOC 2 Change Management control and capture patch‑install logs as audit evidence.
  • Incorporate continuous monitoring of third‑party software updates into your compliance dashboard.

Source: Zero Day Initiative advisory – ZDI‑26‑552 (CVE‑2026‑18293)

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-552/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →