PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97155 Fabasoft CVE debrief

CVE-2026-97155 debrief based on the supplied source corpus. The Fabasoft Folio Client, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. This allows any website to invoke client functions, posing a risk to deployments with untrusted or unauthenticated internet access. Defenders should assess exposure and prioritize remediation to prevent unauthorized function invocation.

Vendor
Fabasoft
Product
Folio Client
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-24
Original CVE updated
2026-09-26
Advisory published
2026-09-24
Advisory updated
2026-09-26

Who should care

Defenders responsible for Fabasoft Folio Client installations should assess exposure and prioritize remediation to prevent unauthorized function invocation. This includes verifying and restricting web origins that can invoke client functions, applying fixed builds, and reviewing the VALIDDOMAINS registry value. Remediation priority is high for deployments with untrusted or unauthenticated internet access.

Why it matters

CVE-2026-97155 allows any website to invoke Fabasoft Folio Client functions by default, posing a risk to deployments with untrusted or unauthenticated internet access. Defenders should prioritize verifying and remediating installations.

  • Defenders must verify and restrict web origins that can invoke Fabasoft Folio Client functions to prevent unauthorized actions.
  • Remediation priority is high for deployments with untrusted or unauthenticated internet access.
  • Verification of client installations and configurations is necessary to ensure security.

Technical summary

Fabasoft Folio Client before 2026 does not restrict which web origins may invoke its functions by default, allowing any website to invoke client functions. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. This vulnerability is addressed in Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76). Defenders should prioritize verifying and remediating installations to prevent unauthorized function invocation.

Defensive priority

Defenders should prioritize verifying and remediating Fabasoft Folio Client installations to prevent unauthorized function invocation.

Recommended defensive actions

  • Verify Fabasoft Folio Client installations and restrict web origins that can invoke client functions.
  • Apply the fixed builds: Fabasoft Folio Client 2026 (Build 26.0.0.10) or Fabasoft Folio Client 2026 April Release (Build 26.4.0.76).
  • Review and update the VALIDDOMAINS registry value to limit permitted origins.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Fabasoft Folio Client, which allows any website to invoke client functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. The first fixed builds are Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97155 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97155

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97155 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97155

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.