CVE-2026-14304

Source
https://cve.org/CVERecord?id=CVE-2026-14304
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14304.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-14304
Published
2026-08-05T10:40:03.743Z
Modified
2026-08-08T03:30:17.361248382Z
Severity
  • 4.6 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.

If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "0.5.0"
                },
                {
                    "last_affected": "1.6.0"
                }
            ]
        }
    ],
    "cna_assigner": "eclipse",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14304.json",
    "cwe_ids": [
        "CWE-611"
    ]
}
References

Affected packages

Git / github.com/eclipse-actf/org.eclipse.actf

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-actf/org.eclipse.actf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "v20260630"
        }
    ]
}

Affected versions

Other
v20230830
v20260630

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-14304.json"