Vulnerability in Fabasoft Folio Client Affects Web Messaging Security
CVE-2026-97155

6.5MEDIUM

Key Information:

Vendor

Fabasoft

Vendor
CVE Published:
24 September 2026

What is CVE-2026-97155?

The Fabasoft Folio Client prior to the 2026 release is susceptible to a security vulnerability due to default settings that permit all domains to invoke client functions via web messaging. This oversight allows malicious websites to potentially exploit the client, performing unauthorized actions such as downloading or opening documents and synchronizing files. The affected versions did not adequately restrict web origins, with the VALIDDOMAINS registry value being optional and defaulting to empty. Users are urged to upgrade to the latest versions to mitigate this risk.

Affected Version(s)

Folio Client Windows 0 < 2026

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.