XML External Entity Vulnerability in Eclipse Accessibility Tools Framework
CVE-2026-14304
4.6MEDIUM
What is CVE-2026-14304?
An XML External Entity (XXE) vulnerability has been identified in the Eclipse Accessibility Tools Framework (ACTF), affecting versions up to 1.6.0, including source code versions up to v20260630. This vulnerability permits unauthorized access to local and internal network resources when applications utilizing Eclipse ACTF, such as miChecker, are exploited by a malicious third party. Proper mitigation strategies should be implemented to safeguard against potential data leakage and resource exposure.
Affected Version(s)
Eclipse Accessibility Tools Framework (ACTF) 0.5.0 <= 1.6.0
Eclipse Accessibility Tools Framework (ACTF) 0
References
CVSS V4
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was reported to IPA by Mr. Yuki Matsuhashi under the Information Security Early Warning Partnership framework. JPCERT/CC coordinated with the application provider and developer. We would like to express our sincere appreciation to Mr. Yuki Matsuhashi and all parties involved for their cooperation.
