Parallels Desktop Mac local root escalation security flaw (CVE-2026-90894)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-90894 in Parallels Desktop for Mac lets a non-admin local account execute code as root on the Mac host through prl_disp_service and tar argument injection. JFrog demonstrated the flaw on Parallels Desktop 26.4.0 and says Parallels Desktop 27.0.0 fixes it. The weakness affects the Mac host, not guest VMs, and JFrog reports no attacks. Administrators should move to the fixed build or restrict local access until patched.
Timeline
-
16.09.2026 16:14 1 articles · 2h ago
Parallels tells Intel Mac users to stay on version 26
Mitigation Patch UpdateOn 25 August 2026, Parallels said Intel-based Mac users could keep using Parallels Desktop 26 and expect future security and maintenance updates. The statement left version 27 as Apple silicon only, which matters because Intel Macs cannot install the fixed 27.x line.
Show sources
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14
-
16.09.2026 16:14 1 articles · 2h ago
JFrog and Parallels give different dates for the 27.0.0 fix
Mitigation Patch UpdateJFrog's disclosure timeline says the fix shipped in Parallels Desktop 27.0.0 on 1 September 2026, but Parallels' release notes place 27.0.0 on 25 August 2026 and 27.0.1 on 1 September 2026. That leaves 27.0.1 as the clearer fixed build for Apple silicon Macs.
Show sources
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14
-
16.09.2026 16:14 1 articles · 2h ago
Parallels Desktop 26.4.2 still lacks a documented extract fix
Mitigation Patch UpdateParallels Desktop 26.4.2, released on 8 September 2026, lists only a deployment problem in the Enterprise edition, and Parallels has not published a record for CVE-2026-90894. JFrog says hosts that remain on the 26.x line, including 26.4.2, do not have the extract change.
Show sources
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14
-
16.09.2026 16:14 2 articles · 2h ago
JFrog publishes CVE-2026-90894 for a Parallels Desktop root escalation
Initial DisclosureJFrog published ParaShells and assigned CVE-2026-90894 to a Parallels Desktop for Mac flaw that lets a non-admin local account use a world-writable dispatcher socket and tar argument injection to run code as root on the host Mac. JFrog says the flaw works without a Parallels code signature, no virtual machine has to be running, and it has seen no attacks.
Show sources
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix — thehackernews.com — 16.09.2026 16:14