CVE-2026-43910 | Appium java-client up to 10.1.0 AppiumCommandExecutor.setDirectConnect server-side request forgery
A vulnerability labeled as critical has been found in Appium java-client up to 10.1.0. The impacted element is the function AppiumCommandExecutor.setDirectConnect. Such manipulation of the argument directConnectHost/directConnectPort/directConnectPath leads to server-side request forgery.
This vulnerability is listed as CVE-2026-43910. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More