Skip to content
Parallels Desktop Vulnerability Allows Local Users to Gain Root Access

Parallels Desktop Vulnerability Allows Local Users to Gain Root Access

First seen 16 Sep 2026, 15:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 16:33 UTC
  • CVE-2026-90894 allows local users to gain root access on vulnerable Macs.
  • The vulnerability affects Parallels Desktop 26.4.0 and potentially older versions.
  • A patch is available in version 27.0.0, but Intel Macs cannot apply it.

A critical vulnerability in Parallels Desktop, identified as CVE-2026-90894 and dubbed 'ParaShells', allows any local user on a Mac to execute code with root privileges. The flaw arises from a world-writable Unix socket and weak local-client authentication in the prl_disp_service, which runs as root. This vulnerability affects Parallels Desktop version 26.4.0 (build 57513) and potentially older versions. The exploit requires a low-privileged local account and does not necessitate a running virtual machine. JFrog, which discovered the flaw, has rated it 7.8 out of 10 in severity. A patch is available in Parallels Desktop version 27.0.0, but Intel Macs cannot install this fix. Organizations are advised to identify affected systems and restrict local accounts until they can upgrade. No active exploitation has been reported yet.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-14
CVE-2026-90894 published
JFrog disclosed the ParaShells vulnerability affecting Parallels Desktop for Mac.
Research.Jfrog
2026-09-14
CVE-2026-76461 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
Public disclosure of exploit details
JFrog published technical details of the ParaShells vulnerability, including the attack vector.
jfrog.com
2026-09-16
Parallels Desktop 27.0.0 released
Parallels released an update to fix the vulnerability, but it is not available for Intel Macs.
Thehackernews

More articles in this cluster (5)

Following this threat?

Track HBO Max and CVE-2026-76461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed