CVE-2026-3862: Cross-Site Scripting Vulnerability in SiteMinder Administrative UI
Published Mar 10, 2026
·Updated
Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.
Affected Software
3 affected components
SiteMinder Administrative UI
Broadcom Symantec Siteminder>=12.8<=12.8.08
Broadcom Symantec Siteminder=12.9
Event History
Mar 10, 2026
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
Description
Data Sourced
via NVD·06:19 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3862?
The severity of CVE-2026-3862 is classified as High due to its potential impact on the SiteMinder Administrative UI.
2
How do I fix CVE-2026-3862?
To fix CVE-2026-3862, update the SiteMinder Administrative UI to the latest version available from Broadcom.
3
What software versions are affected by CVE-2026-3862?
CVE-2026-3862 affects Broadcom Symantec SiteMinder versions 12.8.0 to 12.8.08 and version 12.9.
4
What type of vulnerability is CVE-2026-3862?
CVE-2026-3862 is a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
5
Can CVE-2026-3862 be exploited remotely?
Yes, CVE-2026-3862 can be exploited remotely if an attacker targets an affected instance of SiteMinder Administrative UI.