Dynamics 365 Customer Voice Cross-Site Scripting Spoofing Vulnerability
First seen Jul 9, 2026 · Updated Jul 9, 2026 · CVSS 9.3
CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthorized, unauthenticated attacker to inject malicious scripts and perform spoofing attacks over a network. With a CVSS score of 9.3, this flaw could enable attackers to impersonate legitimate users or interfaces, potentially harvesting credentials or session data submitted through survey forms.
Technical Analysis
CVE-2026-47646 stems from improper neutralization of input during web page generation, a classic XSS vulnerability (CWE-79), within the Dynamics 365 Customer Voice module. An unauthenticated attacker can craft malicious input—likely via survey responses, form fields, or embedded links—that is rendered without proper sanitization, enabling script injection that facilitates UI spoofing to deceive victims into disclosing sensitive information or interacting with attacker-controlled content. The high CVSS score of 9.3 reflects the network attack vector, low complexity, and lack of required privileges, making exploitation broadly accessible. Given Customer Voice's role in collecting customer feedback and integrating with Dynamics 365 CRM workflows, successful exploitation could compromise customer trust data and lateral connections to backend business systems. If organizations use AI agents or LLM-based tools to automatically process, summarize, or respond to Customer Voice survey submissions, injected malicious scripts or spoofed content could poison agent inputs, leading to manipulated outputs, credential exposure, or unauthorized actions taken on behalf of the deceived agent.
Affected Systems
Microsoft Dynamics 365 Customer Voice (all cloud-hosted instances prior to the security patch); organizations using Customer Voice survey forms integrated with Dynamics 365 CRM, Power Automate flows, or third-party CRM connectors.
Indicators of Compromise
- No specific IOCs published at this time; monitor Microsoft Security Response Center (MSRC) advisories for CVE-2026-47646 for updated indicators, malicious survey URLs, or injected script payloads.
Remediation Steps
- 1
Apply Microsoft Security Update
Monitor MSRC and apply the official patch or update for Dynamics 365 Customer Voice as soon as it is released by Microsoft.
- 2
Sanitize and Validate User Input
Implement strict server-side input validation and output encoding for all fields accepting user-submitted content in Customer Voice forms.
- 3
Enable Content Security Policy (CSP)
Deploy CSP headers to restrict execution of unauthorized inline scripts and reduce the impact of potential XSS payloads.
- 4
Audit Automated Processing Pipelines
Review any AI agents, chatbots, or automation workflows that ingest Customer Voice survey data to ensure they treat submitted content as untrusted and sanitize before processing.
- 5
Monitor and Alert
Enable logging and anomaly detection on Customer Voice endpoints to identify suspicious script injection attempts or spoofed content submissions.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.