Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-14304

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-611 Restricción incorrecta de referencia a entidad externa XML (XXE)
Fecha de publicación:
05/08/2026
Última modificación:
10/08/2026

Descripción

*** Pendiente de traducción *** In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists.<br /> <br /> <br /> <br /> If this vulnerability is exploited, a malicious third party could gain access to local resources or internal network resources via computer running applications that use Eclipse ACTF, including miChecker.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:eclipse:accessibility_tools_framework:*:*:*:*:*:*:*:* 0.5.0 (incluyendo) 1.6.0 (incluyendo)
cpe:2.3:a:soumu:michecker:*:*:*:*:*:*:*:* 3.2.0 (excluyendo)