CVE-2026-97155: Medium severity Fabasoft Folio Client vulnerability
Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. As a consequence, any website visited by a user with the Folio Client and browser extension installed could invoke client functions, e.g., related to downloading documents, opening documents, and synchronizing files. The first fixed builds are Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76). This client is, for example, shipped with Fabasoft eGov-Suite.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fabasoft Folio Clientto a version that resolves this vulnerability.Fixed in 26.0.0.10 - Configuration
Set the registry value VALIDDOMAINS to the permitted web origins; existing installations remain insecure until an administrator sets this value manually.
Fabasoft Folio Client VALIDDOMAINS = permitted web origins
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users are exposed if they have both the Fabasoft Folio Client and the Fabasoft browser extension installed and use a version before the fixed builds. The client may also be present as part of products such as Fabasoft eGov-Suite.
What does an attacker need to exploit it?
An attacker only needs to get an affected user to visit a website they control or otherwise cause the user to load malicious web content. No authentication or special privileges are required, but user interaction is required to visit the site.
Are default installations affected?
Yes. By default, the VALIDDOMAINS registry value was optional and empty, which caused the client to trust all web origins rather than restricting which sites could invoke its functions.
What can be done if the client cannot be updated immediately?
Configure the VALIDDOMAINS registry value to limit permitted web origins to the domains that legitimately need to communicate with the Folio Client.
How can I determine whether the issue is remediated?
Verify that the Folio Client is updated to Fabasoft Folio Client 2026 Build 26.0.0.10 or Fabasoft Folio Client 2026 April Release Build 26.4.0.76, or confirm that VALIDDOMAINS is configured with an appropriate restricted list of allowed origins.