What is CVE-2026-43910?
This CVE is a security vulnerability in the Appium Java Client where the `AppiumCommandExecutor.setDirectConnect()` function improperly reads external host, port, and path parameters when `directConnect(true)` is enabled. Affected versions are from 8.2.1 to 10.1.1, and users should update immediately.
Azərbaycanca: Bu CVE Appium Java Client-də `directConnect(true)` aktiv olduqda `AppiumCommandExecutor.setDirectConnect()` funksiyasının xarici host, port və yol parametrlərini düzgün oxumaması səbəbindən yaranan təhlükəsizlik boşluğudur. Təsirə məruz qalan versiyalar 8.2.1-dən 10.1.1-ə qədərdir, istifadəçilər dərhal yenilənməlidir.
FAQ2
In which function of the Appium Java Client was the CVE-2026-43910 vulnerability discovered?
This vulnerability was discovered in the `AppiumCommandExecutor.setDirectConnect()` function.
Which versions of the Appium Java Client should be updated to protect against CVE-2026-43910?
Versions from 8.2.1 to 10.1.1 are affected and should be updated immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.