Looking at how the filter works, it looks like we either find * which allows all origins, or - we look for exact matches in the configuration based upon the Origin HTTP header.

So you can't allow all subdomains in FusionAuth at this time.