Local Privilege Escalation in Parallels RAS Client by Parallels
CVE-2026-18262

7.8HIGH

Key Information:

Vendor

Parallels

Vendor
CVE Published:
20 August 2026

What is CVE-2026-18262?

A local privilege escalation vulnerability exists within the RAS RDP Backend Service of Parallels RAS Client. This flaw allows attackers with low-privileged access to escalate their privileges to the SYSTEM level. By leveraging this vulnerability, an attacker can execute arbitrary code, significantly compromising the affected system's integrity and security. Proper mitigation strategies should be implemented to address this security concern.

Affected Version(s)

RAS Client 21.0.26296

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.