jfrog.com Parallels Desktop Vulnerability Allows Local Users to Gain Root Access
Article Content
- •CVE-2026-90894 allows local users to gain root access on vulnerable Macs.
- •The vulnerability affects Parallels Desktop 26.4.0 and potentially older versions.
- •A patch is available in version 27.0.0, but Intel Macs cannot apply it.
A critical vulnerability in Parallels Desktop, identified as CVE-2026-90894 and dubbed 'ParaShells', allows any local user on a Mac to execute code with root privileges. The flaw arises from a world-writable Unix socket and weak local-client authentication in the prl_disp_service, which runs as root. This vulnerability affects Parallels Desktop version 26.4.0 (build 57513) and potentially older versions. The exploit requires a low-privileged local account and does not necessitate a running virtual machine. JFrog, which discovered the flaw, has rated it 7.8 out of 10 in severity. A patch is available in Parallels Desktop version 27.0.0, but Intel Macs cannot install this fix. Organizations are advised to identify affected systems and restrict local accounts until they can upgrade. No active exploitation has been reported yet.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track HBO Max and CVE-2026-76461 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…