


Perceptive Security
SOC/SIEM Consultancy

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect…
Published:
28 July 2026 at 00:00:00
Alert date:
28 July 2026 at 19:04:58
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization, Supply Chain & Dependencies
CVE-2026-43910 affects Appium Java Client versions 8.2.1 through 10.1.1, where enabling directConnect(true) allows a rogue or compromised Appium server to redirect all session traffic to an arbitrary destination. The vulnerability exists in AppiumCommandExecutor.setDirectConnect(), which reads host, port, and path fields from the server's NEW_SESSION response without validating the host against an allowlist or performing IP validation. This insufficient validation enables full interception of WebDriver session traffic. Additionally, the flaw can be exploited as a Server-Side Request Forgery (SSRF) pivot to reach internal hosts, including cloud metadata services (IMDS), potentially leading to credential theft. The vulnerability is classified as high severity due to the risk of session interception and cloud credential exfiltration. A fix has been released in version 10.1.1 of the Appium Java Client. Users are strongly advised to upgrade immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Appium Java Client 8.2.1 - 10.1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-43910
https://github.com/appium/java-client/commit/2b9cd442b9dbf56ccc6f1e83aeeb411c0ec230c9
https://github.com/appium/java-client/pull/2408
https://github.com/appium/java-client/releases/tag/v10.1.1
https://github.com/appium/java-client/security/advisories/GHSA-28f5-38xr-jh2w
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
