Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Remote Code Execution in OriginLab Origin Viewer (CVE‑2026‑19885) Enables Out‑Of‑Bounds Write

OriginLab’s Origin Viewer contains a CVE‑2026‑19885 out‑of-bounds write that can lead to remote code execution when a malicious OGWU file is opened. The flaw scores 7.8 (High) and is fixed in version 10.4.0.25. For SOC 2‑aligned organizations, unpatched installations represent a control gap that must be documented and remediated.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
zerodayinitiative.com

Remote Code Execution in OriginLab Origin Viewer (CVE‑2026‑19885) – Out‑Of‑Bounds Write in OGWU Parsing

What It Is — A CVE‑2026‑19885 vulnerability in OriginLab Origin Viewer allows remote attackers to execute arbitrary code by supplying a crafted OGWU file. The flaw is an out‑of‑bounds write caused by insufficient validation of file‑contained data.

Exploitability — Requires user interaction (opening a malicious file or visiting a page that triggers the viewer). CVSS 7.8 (High), vector AV:L/AC:L/PR:N/UI:R. No public exploit is known, but a proof‑of‑concept exists.

Affected Products — OriginLab Origin Viewer (all versions prior to 10.4.0.25).

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous control mapping: the vulnerability maps to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations).
  • Evidence of timely patch management is a key audit artifact; organizations must prove they applied the vendor’s fix.
  • Unpatched software can be cited as a control gap during third‑party risk assessments, affecting the Trust Center evidence set.

Recommended Actions

  • Verify all endpoints run Origin Viewer 10.4.0.25 or later; inventory any older versions.
  • Deploy the vendor patch immediately and document the change in your configuration‑management system.
  • Update your SOC 2 control mapping to include OGWU file parsing under “Secure Development” and capture patch‑deployment evidence for audit.
  • Enable file‑integrity monitoring and log any attempts to open OGWU files for anomaly detection.

Source: Zero Day Initiative Advisory – ZDI‑26‑585

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-585/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →