PT-2026-97701 · Fabasoft · Fabasoft Folio Client

CVE-2026-97155

·

Published

2026-09-24

·

Updated

2026-09-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fabasoft Folio Client versions prior to 2026
Description A locally installed component that communicates with the browser extension via web messaging does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, causing all domains to be trusted. Consequently, any website visited by a user with the client and extension installed could invoke functions related to downloading documents, opening documents, and synchronizing files.
Recommendations Update to Fabasoft Folio Client 2026 (Build 26.0.0.10) or Fabasoft Folio Client 2026 April Release (Build 26.4.0.76).

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97155

Affected Products

Fabasoft Folio Client