[Japanese]

JVNDB-2026-000111

miChecker improper restriction of XML external entity references

Overview

miChecker developed by Eclipse Foundation and provided by Ministry of Internal Affairs and Communications contains the following vulnerability.
  • Improper restriction of XML external entity reference (CWE-611) - CVE-2026-14304
Yuki Matsuhashi reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 3.3 (Low) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
CVSS v4 Severity
Base Metrics: 4.6 (Medium) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): Active
  • Vulnerable System Impact
  • Confidentiality Impact (VC): Low
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


Ministry of Internal Affairs and Communications
  • miChecker versions 3.10 and earlier

Impact

The affected product may communicate unintentionally by reading a crafted subtitle, which may lead local resources or internal network resources to be accessed.
Solution

[Update the software]
Update the software to the latest version according to the information provided by the developer.

[Apply the Workaround]
If users cannot update the software to the latest version, the effect of the vulnerability can be avoided by stopping using the "Open caption(SMIL) File" function of the product.
Vendor Information

Eclipse Foundation Ministry of Internal Affairs and Communications
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-14304
References

  1. JVN : JVN#40688603
Revision History

  • [2026/08/17]
      Web page was published