Local Privilege Escalation in Parallels Desktop for Mac by Parallels
CVE-2026-90894

7.8HIGH

Key Information:

Vendor

Parallels

Vendor
CVE Published:
14 September 2026

Badges

👾 Exploit Exists

What is CVE-2026-90894?

A local privilege escalation vulnerability exists in Parallels Desktop for Mac due to the handling of the prl_disp_service running as root. The service listens on a world-writable socket, allowing unauthorized local clients to interact with it without proper permissions. The vulnerability facilitates an exploitable scenario where a specially crafted appliance folder name can lead to additional tar flags being executed as root, potentially compromising the system's integrity and security.

Affected Version(s)

Parallels Desktop for Mac macOS 26.4.0

Parallels Desktop for Mac macOS 27.0.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuval Moravchick | JFrog
.