CVE-2026-3862

MEDIUM

Broadcom SiteMinder - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.

Scores

CVSS v3 4.8
EPSS 0.0004
EPSS Percentile 11.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
Broadcom/SiteMinder 12.8.x
Broadcom/SiteMinder 12.9
broadcom/symantec_siteminder 12.9
broadcom/symantec_siteminder 12.8 - 12.8.08
Published Mar 10, 2026
Tracked Since Mar 11, 2026