top of page
perceptive_background_267k.jpg

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect…

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 19:04:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization, Supply Chain & Dependencies

CVE-2026-43910 affects Appium Java Client versions 8.2.1 through 10.1.1, where enabling directConnect(true) allows a rogue or compromised Appium server to redirect all session traffic to an arbitrary destination. The vulnerability exists in AppiumCommandExecutor.setDirectConnect(), which reads host, port, and path fields from the server's NEW_SESSION response without validating the host against an allowlist or performing IP validation. This insufficient validation enables full interception of WebDriver session traffic. Additionally, the flaw can be exploited as a Server-Side Request Forgery (SSRF) pivot to reach internal hosts, including cloud metadata services (IMDS), potentially leading to credential theft. The vulnerability is classified as high severity due to the risk of session interception and cloud credential exfiltration. A fix has been released in version 10.1.1 of the Appium Java Client. Users are strongly advised to upgrade immediately to mitigate the risk.

Technical details

Mitigation steps:

Affected products:

Appium Java Client 8.2.1 - 10.1.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page