criticalOther

Dynamics 365 Customer Voice Cross-Site Scripting Spoofing Vulnerability

First seen Jul 9, 2026 · Updated Jul 9, 2026 · CVSS 9.3

xssspoofingdynamics-365customer-voicemicrosoftweb-vulnerabilityinput-validation

CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthorized, unauthenticated attacker to inject malicious scripts and perform spoofing attacks over a network. With a CVSS score of 9.3, this flaw could enable attackers to impersonate legitimate users or interfaces, potentially harvesting credentials or session data submitted through survey forms.

Technical Analysis

CVE-2026-47646 stems from improper neutralization of input during web page generation, a classic XSS vulnerability (CWE-79), within the Dynamics 365 Customer Voice module. An unauthenticated attacker can craft malicious input—likely via survey responses, form fields, or embedded links—that is rendered without proper sanitization, enabling script injection that facilitates UI spoofing to deceive victims into disclosing sensitive information or interacting with attacker-controlled content. The high CVSS score of 9.3 reflects the network attack vector, low complexity, and lack of required privileges, making exploitation broadly accessible. Given Customer Voice's role in collecting customer feedback and integrating with Dynamics 365 CRM workflows, successful exploitation could compromise customer trust data and lateral connections to backend business systems. If organizations use AI agents or LLM-based tools to automatically process, summarize, or respond to Customer Voice survey submissions, injected malicious scripts or spoofed content could poison agent inputs, leading to manipulated outputs, credential exposure, or unauthorized actions taken on behalf of the deceived agent.

Affected Systems

Microsoft Dynamics 365 Customer Voice (all cloud-hosted instances prior to the security patch); organizations using Customer Voice survey forms integrated with Dynamics 365 CRM, Power Automate flows, or third-party CRM connectors.

Indicators of Compromise

  • No specific IOCs published at this time; monitor Microsoft Security Response Center (MSRC) advisories for CVE-2026-47646 for updated indicators, malicious survey URLs, or injected script payloads.

Remediation Steps

  1. 1

    Apply Microsoft Security Update

    Monitor MSRC and apply the official patch or update for Dynamics 365 Customer Voice as soon as it is released by Microsoft.

  2. 2

    Sanitize and Validate User Input

    Implement strict server-side input validation and output encoding for all fields accepting user-submitted content in Customer Voice forms.

  3. 3

    Enable Content Security Policy (CSP)

    Deploy CSP headers to restrict execution of unauthorized inline scripts and reduce the impact of potential XSS payloads.

  4. 4

    Audit Automated Processing Pipelines

    Review any AI agents, chatbots, or automation workflows that ingest Customer Voice survey data to ensure they treat submitted content as untrusted and sanitize before processing.

  5. 5

    Monitor and Alert

    Enable logging and anomaly detection on Customer Voice endpoints to identify suspicious script injection attempts or spoofed content submissions.

CVE / Advisory IDs

CVE-2026-47646

Industries Most Exposed

RetailFinancial ServicesHealthcareTechnologyCustomer ServiceAny industry using Dynamics 365 CRM

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.