CVE-2026-97155 Details
Description
Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. As a consequence, any website visited by a user with the Folio Client and browser extension installed could invoke client functions, e.g., related to downloading documents, opening documents, and synchronizing files. The first fixed builds are Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76). This client is, for example, shipped with Fabasoft eGov-Suite.
A vulnerability exists in the Fabasoft Folio Client component prior to 2026, which allows any website to invoke client functions through web messaging. This issue arises because the client does not properly restrict which web origins can access its functions by default. The registry value VALIDDOMAINS, intended to limit permitted origins, was optional and empty by default, leading to a trust-all-domains scenario. As a result, websites could manipulate client functions related to document management and file synchronization. The vulnerability affects Fabasoft Folio Client versions prior to 2026, including those bundled with Fabasoft eGov-Suite.
Users can update to Fabasoft Folio Client 2026 (Build 26.0.0.10) or Fabasoft Folio Client 2026 April Release (Build 26.4.0.76), where this vulnerability is addressed. After updating, the VALIDDOMAINS registry key must be configured to specify which domains are allowed to interact with the client. This can be done manually or during installation by providing the list of domains as an installer argument.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.supportservices.fabasoft.com/index.php?topic=doc/Knowledge-Base/changes-to-fabasoft-folio-client-security-settings.htm | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Fabasoft Folio Client | 26.0.0.10 26.4.0.76 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion