Local Privilege Escalation in Parallels Desktop for Mac by Parallels
CVE-2026-90894
7.8HIGH
What is CVE-2026-90894?
A local privilege escalation vulnerability exists in Parallels Desktop for Mac due to the handling of the prl_disp_service running as root. The service listens on a world-writable socket, allowing unauthorized local clients to interact with it without proper permissions. The vulnerability facilitates an exploitable scenario where a specially crafted appliance folder name can lead to additional tar flags being executed as root, potentially compromising the system's integrity and security.
Affected Version(s)
Parallels Desktop for Mac macOS 26.4.0
Parallels Desktop for Mac macOS 27.0.1
