PT-2026-97701 · Fabasoft · Fabasoft Folio Client
CVE-2026-97155
·
Published
2026-09-24
·
Updated
2026-09-26
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Fabasoft Folio Client versions prior to 2026
Description
A locally installed component that communicates with the browser extension via web messaging does not restrict which web origins may invoke its functions by default. The registry value
VALIDDOMAINS, which limits permitted origins, was optional and empty by default, causing all domains to be trusted. Consequently, any website visited by a user with the client and extension installed could invoke functions related to downloading documents, opening documents, and synchronizing files.Recommendations
Update to Fabasoft Folio Client 2026 (Build 26.0.0.10) or Fabasoft Folio Client 2026 April Release (Build 26.4.0.76).
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fabasoft Folio Client