XML External Entity (XXE) Vulnerability in Eclipse ACTF (including miChecker)
Published: July 30, 2026
Overview
It has been identified that an XML External Entity (XXE) vulnerability exists in Eclipse Accessibility Tools Framework (ACTF) versions up to 20260630 (including miChecker v3.1.0). If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. Please review the affected versions of Eclipse ACTF and miChecker listed below and apply the recommended update.
How to Check Affected Applications
- Application Name: miChecker
- Affected Versions: All versions up to and including 3.1.0
- Launch miChecker and select “About miChecker” from the “Help” menu.
- The version number of miChecker will be displayed at the top center of the window.
Description of the Vulnerability
miChecker uses XML parsing functionality to verify and display caption files. Due to implementation of this functionality, an XML External Entity (XXE) vulnerability exists. By loading a specially crafted caption file, unintended communications may occur from the application, allowing external third parties to access local resources or internal network resources.
Potential Impact
- XML External Entity (XXE) Vulnerability ( CWE-611 )
- CVSS4.0: AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N (Base Score:4.6)
- CVSS3.0: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N (Base Score: 3.3)
- CVE-2026-14304
Mitigation / Solution
Users of miChecker version 3.1.0 or earlier should uninstall the application once and then install the patched version (miChecker version 3.1.1 or later). For instructions on obtaining and installing the updated version, please refer to miChecker download page (in Japanese, Jump to MIC Web site) .
Workaround
The impact of this vulnerability may be mitigated by the following measure:
Workaround: Avoid using the “Open caption(SMIL) File” function in miChecker.
Related Information
JVN# 40688603: XML External Entity (XXE) Vulnerability in miChecker
Acknowledgements
This vulnerability was reported to IPA by Mr. Yuki Matsuhashi under the Information Security Early Warning
Partnership framework. JPCERT/CC coordinated with the application provider and developer.
We would like to express
our sincere appreciation to Mr. Yuki Matsuhashi and all parties involved for their cooperation.
Contact Information
Eclipse Security Contact
Eclipse ACTF Contact (Mailing List)
actf-dev Mailing List (registration required)
Revision History
July 30, 2026: Initial publication of this vulnerability information.