Impact
An XML External Entity (XXE) flaw exists in Eclipse Accessibility Tools Framework (ACTF) that can let a malicious party read local or internal network files when an application processes certain XML inputs. The weakness is classified as CWE‑611 and can cause the attacker to access sensitive data beyond the intended scope of the application, though it does not give full remote code execution.
Affected Systems
The vulnerability affects Eclipse Foundation’s Eclipse Accessibility Tools Framework up to version 1.6.0, including source code versions up to v20260630, and the miChecker application based on ACTF up to version 3.1.0. Any program employing these components and parsing XML can be impacted.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, no widely published exploits are known. The likely attack vector is a local attacker or a compromised application that feeds crafted XML into ACTF, enabling the attacker to read local or network files accessible to the application’s process.
OpenCVE Enrichment