Eclipse Foundation Eclipse Accessibility Tools Framework

XML External Entity (XXE) Vulnerability in Eclipse ACTF (including miChecker)

Published: July 30, 2026

Overview

It has been identified that an XML External Entity (XXE) vulnerability exists in Eclipse Accessibility Tools Framework (ACTF) versions up to 20260630 (including miChecker v3.1.0). If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker. Please review the affected versions of Eclipse ACTF and miChecker listed below and apply the recommended update.

How to Check Affected Applications

The application affected by this vulnerability is:
  • Application Name: miChecker
  • Affected Versions: All versions up to and including 3.1.0
To check the version you are using:
  1. Launch miChecker and select “About miChecker” from the “Help” menu.
  2. The version number of miChecker will be displayed at the top center of the window.
(If you are developing applications using the Eclipse ACTF source code, versions based on source code downloaded from tags up to 20260630 may also be affected by this vulnerability.)

Description of the Vulnerability

miChecker uses XML parsing functionality to verify and display caption files. Due to implementation of this functionality, an XML External Entity (XXE) vulnerability exists. By loading a specially crafted caption file, unintended communications may occur from the application, allowing external third parties to access local resources or internal network resources.

Potential Impact

If an attacker successfully exploits this vulnerability by loading a crafted caption file through the “Open Subtitle (SMIL format)” feature, there is a risk that malicious third parties may gain access to local resources or internal network resources on the computer.
  • XML External Entity (XXE) Vulnerability ( CWE-611
  • CVSS4.0: AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N (Base Score:4.6)
  • CVSS3.0: AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N (Base Score: 3.3)
  • CVE-2026-14304

Mitigation / Solution

Users of miChecker version 3.1.0 or earlier should uninstall the application once and then install the patched version (miChecker version 3.1.1 or later). For instructions on obtaining and installing the updated version, please refer to miChecker download page (in Japanese, Jump to MIC Web site) .

Workaround

The impact of this vulnerability may be mitigated by the following measure:

Workaround: Avoid using the “Open caption(SMIL) File” function in miChecker.

Related Information

JVN# 40688603: XML External Entity (XXE) Vulnerability in miChecker

Acknowledgements

This vulnerability was reported to IPA by Mr. Yuki Matsuhashi under the Information Security Early Warning Partnership framework. JPCERT/CC coordinated with the application provider and developer.
We would like to express our sincere appreciation to Mr. Yuki Matsuhashi and all parties involved for their cooperation.

Contact Information

Eclipse Security Contact

Eclipse Foundation Security

Eclipse ACTF Contact (Mailing List)

actf-dev Mailing List (registration required)

Revision History

July 30, 2026: Initial publication of this vulnerability information.

Back to the top


About miChecker