CVE-2026-14304
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.
| CWE | CWE-611 |
| Vendor | eclipse foundation |
| Product | eclipse accessibility tools framework (actf) |
| Published | Aug 5, 2026 |
| Last Updated | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse accessibility tools framework (actf)
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse accessibility tools framework (actf) are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Accessibility Tools Framework (ACTF)
0.5.0 โค 1.6.0 0 โค v20260630
References
eclipse.dev: https://eclipse.dev/actf/downloads/tools/miChecker/vulnerability.html soumu.go.jp: https://www.soumu.go.jp/info-accessibility-portal/webaccessibility/michecker/ github.com: https://github.com/eclipse-actf/org.eclipse.actf gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/151
Credits
This vulnerability was reported to IPA by Mr. Yuki Matsuhashi under the Information Security Early Warning Partnership framework. JPCERT/CC coordinated with the application provider and developer. We would like to express our sincere appreciation to Mr. Yuki Matsuhashi and all parties involved for their cooperation.