PT-2026-91137 · Parallels · Parallels Desktop

CVE-2026-90894

·

Published

2026-09-14

·

Updated

2026-09-23

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Parallels Desktop versions prior to 27.0.0
Description A local privilege escalation issue exists in Parallels Desktop for Mac where an unprivileged local user can execute code as root. The prl disp service daemon runs with root privileges and exposes a world-writable Unix-domain socket at /var/run/prl disp service.socket. The daemon uses PrlSrv LoginLocal to authenticate clients via kernel peer credentials without validating a Parallels Team ID or code signature, allowing unsigned clients to log in.
Following authentication, the PrlSrv InstallAppliance function allows the user to specify an appliance folder via the sVmParentPath variable. The daemon constructs a tar command string that is processed by QProcess::splitCommand. By including a quote in the sVmParentPath value, an attacker can perform argument injection to insert the --use-compress-program flag. Since the tar process is launched as root, the program specified in this flag is also executed with root privileges.
Recommendations Update Parallels Desktop to version 27.0.0 or later. Restrict local access to systems running versions prior to 27.0.0, particularly on Intel-based Macs where the updated version may not be supported.

Fix

RCE

LPE

Argument Injection

OS Command Injection

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90894

Affected Products

Parallels Desktop