Description
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-07-08
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of user input during web page generation, classified as a Cross‑Site Scripting flaw (CWE‑79). It allows an unauthorized attacker to inject malicious content into pages served by Dynamics 365 Customer Voice, making other users believe the attacker is a legitimate participant or source. This deception can erode trust and potentially enable further phishing or social engineering attacks.

Affected Systems

Microsoft Dynamics 365 Customer Voice is affected. No specific version list is provided by the CNA; therefore all deployed instances of the product may be vulnerable until patched.

Risk and Exploitability

The CVSS score is 9.3, indicating a high‑severity risk. The EPSS score is < 1 %, showing a very low but nonzero likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by supplying crafted input that is reflected or stored without proper sanitization, enabling the delivery of deceptive content that appears authentic to other users. Because the flaw does not require authentication, any user interacting with the web interface could be impacted.

Generated by OpenCVE AI on July 26, 2026 at 16:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for Dynamics 365 Customer Voice that addresses the XSS flaw.
  • Configure a Web Application Firewall or equivalent protection to detect and block suspicious script injection attempts and to log potential exploitation attempts.
  • Implement a Content Security Policy and enforce strict input validation on all user‑supplied data to reduce the risk of successful XSS attacks.

Generated by OpenCVE AI on July 26, 2026 at 16:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
Title Dynamics 365 Customer Voice Spoofing Vulnerability
First Time appeared Microsoft
Microsoft dynamics 365 Customer Voice
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:dynamics_365_customer_voice:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft dynamics 365 Customer Voice
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Dynamics 365 Customer Voice
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-28T22:20:28.497Z

Reserved: 2026-05-19T20:12:27.071Z

Link: CVE-2026-47646

cve-icon Vulnrichment

Updated: 2026-07-09T18:26:37.846Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')