CVE-2026-14304Disclosure(eclipse / accessibility_tools_framework)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch eclipse accessibility_tools_framework systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • accessibility_tools_framework
  • michecker

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
accessibility_tools_frameworkmichecker

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-05: 1Mentions · 2026-08-06: 1Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-17: 108-0508-0608-17
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-051
Disclosure1
2026-08-061
General1
2026-08-171
Patch1
Full discourse3 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    CyberSec Daily ✓ · 🧩 Vulnerability · August 17, 2026 🎯 miChecker affected by new XML External Entity vulnerability — CVE-2026-14304 A newly published JVN advisory details an XML External Entity (XXE) vulnerability affecting miChecker. Tracked as CVE-2026-14304, the issue can be triggered when the application processes a specially crafted subtitle file. JVN says exploitation could cause unintended communications from the application and potentially expose access to local or internal network resources. The issue affects miChecker 3.10 and earlier, and users should update to the latest version. 🔗 Source: JVN / JPCERT/CC / IPA #CVE202614304 #XXE #AppSec #CyberSecurity #VulnerabilityManagement #SecurityUpdate

    Post summary

    A new XML External Entity (XXE) vulnerability, CVE‑2026‑14304, affects miChecker versions 3.10 and earlier; the advisory recommends updating to the latest version to mitigate the issue.

    0001065
    72 followersView on X
  • sgy@__sgy__
    General

    これか https://nvd.nist.gov/vuln/detail/CVE-2026-14304

    Post summary

    The post simply links to the CVE entry without providing any additional technical or exploit information.

    00010112
    225 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-14304 XML External Entity Vulnerability in Eclipse ACTF Versions Up to 1.6.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-14304

    Post summary

    The text announces an XML External Entity vulnerability in Eclipse ACTF versions up to 1.6.0, providing technical details but no PoC, exploit, or patch information.

    0000085
    4.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appeclipseaccessibility_tools_framework---
Appsoumumichecker---

Explore more