Local Privilege Escalation Vulnerability in Parallels RAS Client by Parallels
CVE-2026-13121

7.8HIGH

Key Information:

Vendor

Parallels

Vendor
CVE Published:
20 August 2026

What is CVE-2026-13121?

A local privilege escalation vulnerability exists in the RAS RDP Backend Service of Parallels RAS Client. This flaw arises from an exposed dangerous function which allows an attacker with limited privileges to escalate their access and execute arbitrary code in the context of the SYSTEM user. Successful exploitation requires that the attacker initially has the capability to run low-privileged code on the system.

Affected Version(s)

RAS Client 21.0.26296

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.