Impact
Fabasoft Folio Client prior to version 2026 does not enforce any whitelist of web origins when receiving messages from the Fabasoft browser extension. By default the registry value VALIDDOMAINS is empty, meaning all sites are considered trusted. A web page that a user visits can therefore trigger client operations such as downloading, opening, or synchronizing documents, potentially exposing the user’s data and permitting further compromise. The weakness is a classic example of CWE‑346 where an application accepts input from an untrusted domain without validation.
Affected Systems
The vulnerability affects all installations of Fabasoft Folio Client before the 2026 release (including builds 26.0.0.10 and 26.4.0.76 that are the first secured builds). Existing deployments remain vulnerable until an administrator configures the VALIDDOMAINS registry value manually. The product is typically bundled with the Fabasoft eGov‑Suite, making many public‑sector environments likely to be impacted.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity that could lead to unauthorized data access or manipulation. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Exploitation requires a user to visit a malicious web page while they have the Folio Client and extension installed; no network‑level access is needed. Once the browser triggers the message, the client performs privileged actions without further authentication. Therefore, the risk is chiefly dependent on user browsing habits, but the impact is significant if the client handles sensitive or regulated documents.
OpenCVE Enrichment