CVE-2026-32699: Neorazorx Facturascripts

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fails to validate the nick parameter during a POST request to the EditUser controller. Although the user interface prevents editing this field, a user can bypass this restriction by intercepting the request and modifying the nick form-data parameter to rename any account, including the administrator account. This leads to unauthorized modification of a field intended to be immutable.

Affected products

  • Neorazorx Facturascripts: up to and including 2025.92

Published 2026-05-05. Last modified 2026-07-25.