PT-2026-91137 · Parallels · Parallels Desktop
CVE-2026-90894
·
Published
2026-09-14
·
Updated
2026-09-23
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Parallels Desktop versions prior to 27.0.0
Description
A local privilege escalation issue exists in Parallels Desktop for Mac where an unprivileged local user can execute code as root. The
prl disp service daemon runs with root privileges and exposes a world-writable Unix-domain socket at /var/run/prl disp service.socket. The daemon uses PrlSrv LoginLocal to authenticate clients via kernel peer credentials without validating a Parallels Team ID or code signature, allowing unsigned clients to log in.Following authentication, the
PrlSrv InstallAppliance function allows the user to specify an appliance folder via the sVmParentPath variable. The daemon constructs a tar command string that is processed by QProcess::splitCommand. By including a quote in the sVmParentPath value, an attacker can perform argument injection to insert the --use-compress-program flag. Since the tar process is launched as root, the program specified in this flag is also executed with root privileges.Recommendations
Update Parallels Desktop to version 27.0.0 or later.
Restrict local access to systems running versions prior to 27.0.0, particularly on Intel-based Macs where the updated version may not be supported.
Fix
RCE
LPE
Argument Injection
OS Command Injection
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Parallels Desktop