Find notable cyber news and cases, enriched with sources, timelines, and signals.

Parallels Desktop Mac local root escalation security flaw (CVE-2026-90894)

Vulnerability
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-90894 in Parallels Desktop for Mac lets a non-admin local account execute code as root on the Mac host through prl_disp_service and tar argument injection. JFrog demonstrated the flaw on Parallels Desktop 26.4.0 and says Parallels Desktop 27.0.0 fixes it. The weakness affects the Mac host, not guest VMs, and JFrog reports no attacks. Administrators should move to the fixed build or restrict local access until patched.

Timeline

  1. 16.09.2026 16:14 1 articles · 2h ago

    Parallels tells Intel Mac users to stay on version 26

    Mitigation Patch Update

    On 25 August 2026, Parallels said Intel-based Mac users could keep using Parallels Desktop 26 and expect future security and maintenance updates. The statement left version 27 as Apple silicon only, which matters because Intel Macs cannot install the fixed 27.x line.

    Show sources
  2. 16.09.2026 16:14 1 articles · 2h ago

    JFrog and Parallels give different dates for the 27.0.0 fix

    Mitigation Patch Update

    JFrog's disclosure timeline says the fix shipped in Parallels Desktop 27.0.0 on 1 September 2026, but Parallels' release notes place 27.0.0 on 25 August 2026 and 27.0.1 on 1 September 2026. That leaves 27.0.1 as the clearer fixed build for Apple silicon Macs.

    Show sources
  3. 16.09.2026 16:14 1 articles · 2h ago

    Parallels Desktop 26.4.2 still lacks a documented extract fix

    Mitigation Patch Update

    Parallels Desktop 26.4.2, released on 8 September 2026, lists only a deployment problem in the Enterprise edition, and Parallels has not published a record for CVE-2026-90894. JFrog says hosts that remain on the 26.x line, including 26.4.2, do not have the extract change.

    Show sources
  4. 16.09.2026 16:14 2 articles · 2h ago

    JFrog publishes CVE-2026-90894 for a Parallels Desktop root escalation

    Initial Disclosure

    JFrog published ParaShells and assigned CVE-2026-90894 to a Parallels Desktop for Mac flaw that lets a non-admin local account use a world-writable dispatcher socket and tar argument injection to run code as root on the host Mac. JFrog says the flaw works without a Parallels code signature, no virtual machine has to be running, and it has seen no attacks.

    Show sources