CVE-2026-14304 PUBLISHED

Assigner: eclipse
Reserved: 01.07.2026 Published: 05.08.2026 Updated: 05.08.2026

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.

If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.6

Product Status

Vendor Eclipse Foundation
Product Eclipse Accessibility Tools Framework (ACTF)
Versions Default: unaffected
  • affected from 0.5.0 to 1.6.0 (incl.)
  • affected from 0 to v20260630 (incl.)

Credits

  • This vulnerability was reported to IPA by Mr. Yuki Matsuhashi under the Information Security Early Warning Partnership framework. JPCERT/CC coordinated with the application provider and developer. We would like to express our sincere appreciation to Mr. Yuki Matsuhashi and all parties involved for their cooperation. finder

References

Problem Types

  • CWE-611 CWE

Impacts

  • CAPEC-221