Critical Out‑of‑Bounds Write RCE in OriginLab Origin Viewer (CVE‑2026‑18293)
What It Is — OriginLab’s Origin Viewer contains an out‑of‑bounds write in its OPJ file parser that can be triggered by a crafted OPJ file. The flaw allows an attacker to execute arbitrary code in the context of the viewer process.
Exploitability — CVSS 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). No public exploit is known, but the vulnerability is exploitable when a user opens a malicious file or visits a malicious page that forces the viewer to load the file.
Affected Products — OriginLab Origin Viewer (all versions prior to the 2026‑08‑11 security update).
Why It Matters for Compliance & Audit Readiness
- Change Management (SOC 2 CC6.1) – Demonstrating that you have a process to detect, assess, and remediate third‑party software vulnerabilities is a core audit requirement.
- System Operations (SOC 2 CC7.1) – Evidence of timely patch deployment shows you maintain the integrity of production systems.
- Risk Management – Unpatched scientific‑analysis tools can become an attack vector that jeopardizes data confidentiality and availability, impacting the trust you provide to research partners and funders.
Recommended Actions
- Deploy OriginLab’s patch immediately and verify the installed version.
- Update your asset inventory to flag all endpoints running Origin Viewer.
- Map the vulnerability to your SOC 2 Change Management control and capture patch‑install logs as audit evidence.
- Incorporate continuous monitoring of third‑party software updates into your compliance dashboard.
Source: Zero Day Initiative advisory – ZDI‑26‑552 (CVE‑2026‑18293)