CVE-2026-14304
Received Received - Intake

XXE Vulnerability in Eclipse ACTF and miChecker

Vulnerability report for CVE-2026-14304, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Eclipse Foundation

Description

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
eclipse accessibility_tools_framework to 1.6.0 (inc)
eclipse michecker to 3.1.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an XML External Entity (XXE) vulnerability in Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 and miChecker versions up to 3.1.0. It allows malicious actors to access local or internal network resources through applications using ACTF, such as miChecker, by exploiting improper XML parsing in the caption file verification feature.

Detection Guidance

To detect this XXE vulnerability in Eclipse ACTF or miChecker, check the installed version of miChecker by running: miChecker -v or checking the version in the application settings. If the version is 3.1.0 or earlier, the system is vulnerable. Additionally, inspect XML or SMIL files processed by miChecker for external entity references.

Impact Analysis

If exploited, this vulnerability could allow attackers to access sensitive local files or internal network resources on your system through applications using vulnerable versions of ACTF or miChecker. Users should update to miChecker v3.2.0+ or ACTF v20260730+ to mitigate risks.

Mitigation Strategies

Immediately upgrade miChecker to version 3.2.0 or later. Alternatively, disable the vulnerable 'Open Subtitle (SMIL format)' function in miChecker until the update is applied. Ensure all ACTF-based applications are updated to source code tagged v20260730 or later.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14304. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart