CVE-2026-97155: Medium severity Fabasoft Folio Client vulnerability

Published Sep 24, 2026
·
Updated

Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. As a consequence, any website visited by a user with the Folio Client and browser extension installed could invoke client functions, e.g., related to downloading documents, opening documents, and synchronizing files. The first fixed builds are Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76). This client is, for example, shipped with Fabasoft eGov-Suite.

Affected Software

1 affected component
Fabasoft Folio Client<2026

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Fabasoft Folio Client to a version that resolves this vulnerability.

    Fixed in 26.0.0.10
  2. Configuration

    Set the registry value VALIDDOMAINS to the permitted web origins; existing installations remain insecure until an administrator sets this value manually.

    Fabasoft Folio Client VALIDDOMAINS = permitted web origins

Event History

Sep 24, 2026
CVE Published
via MITRE·03:30 AM
Data Sourced
via MITRE·03:30 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:18 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Users are exposed if they have both the Fabasoft Folio Client and the Fabasoft browser extension installed and use a version before the fixed builds. The client may also be present as part of products such as Fabasoft eGov-Suite.

2

What does an attacker need to exploit it?

An attacker only needs to get an affected user to visit a website they control or otherwise cause the user to load malicious web content. No authentication or special privileges are required, but user interaction is required to visit the site.

3

Are default installations affected?

Yes. By default, the VALIDDOMAINS registry value was optional and empty, which caused the client to trust all web origins rather than restricting which sites could invoke its functions.

4

What can be done if the client cannot be updated immediately?

Configure the VALIDDOMAINS registry value to limit permitted web origins to the domains that legitimately need to communicate with the Folio Client.

5

How can I determine whether the issue is remediated?

Verify that the Folio Client is updated to Fabasoft Folio Client 2026 Build 26.0.0.10 or Fabasoft Folio Client 2026 April Release Build 26.4.0.76, or confirm that VALIDDOMAINS is configured with an appropriate restricted list of allowed origins.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203