Description
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-08
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue is an improper neutralization of user input during web page generation, classified as a Cross‑Site Scripting flaw (CWE‑79). An attacker with no authentication can inject malicious content into pages served by Dynamics 365 Customer Voice, causing other users to perceive the injected content as originating from a legitimate source and potentially leading to confusion or other deception attempts.

Affected Systems

Microsoft Dynamics 365 Customer Voice is affected. No specific affected version list is provided by the CNA; therefore all deployed instances of the product may be vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 9.3 indicates a high‑severity risk, while the EPSS score of < 1 % shows a very low but nonzero likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by supplying crafted input that is reflected or stored without proper sanitization, enabling the delivery of deceptive content that appears authentic to other users. Because the flaw does not require authentication, any user interacting with the web interface could be impacted.

Generated by OpenCVE AI on July 31, 2026 at 13:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for Dynamics 365 Customer Voice that fixes the XSS flaw.
  • Configure a Web Application Firewall or equivalent solution to detect and block suspicious script injection attempts and to log potential exploitation attempts.
  • Enforce a Content Security Policy and implement strict input validation on all user‑supplied data to reduce the risk of successful XSS attacks.

Generated by OpenCVE AI on July 31, 2026 at 13:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
Title Dynamics 365 Customer Voice Spoofing Vulnerability
First Time appeared Microsoft
Microsoft dynamics 365 Customer Voice
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:dynamics_365_customer_voice:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft dynamics 365 Customer Voice
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Dynamics 365 Customer Voice
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-14T16:20:54.126Z

Reserved: 2026-05-19T20:12:27.071Z

Link: CVE-2026-47646

cve-icon Vulnrichment

Updated: 2026-07-09T18:26:37.846Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-09T00:17:23.160

Modified: 2026-07-09T19:17:05.330

Link: CVE-2026-47646

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')