Vulnerability in Fabasoft Folio Client Affects Web Messaging Security
CVE-2026-97155
6.5MEDIUM
What is CVE-2026-97155?
The Fabasoft Folio Client prior to the 2026 release is susceptible to a security vulnerability due to default settings that permit all domains to invoke client functions via web messaging. This oversight allows malicious websites to potentially exploit the client, performing unauthorized actions such as downloading or opening documents and synchronizing files. The affected versions did not adequately restrict web origins, with the VALIDDOMAINS registry value being optional and defaulting to empty. Users are urged to upgrade to the latest versions to mitigate this risk.
Affected Version(s)
Folio Client Windows 0 < 2026
