Parallels Desktop ParaShells LPE to root (CVE-2026-90894); fix in 27.0.0 — Intel Macs cannot install
JFrog (15 September 2026) documents ParaShells: an unprivileged local user on macOS can get root via Parallels Desktop's prl_disp_service (world-writable Unix socket, weak local-client auth, appliance-extract argument injection into tar --use-compress-program). Lab-proven on Desktop 26.4.0 build 57513 (Apple silicon); treat installs that still expose the same InstallAppliance extract template and dispatcher socket as in scope. CVE-2026-90894. Fixed in Parallels Desktop 27.0.0 (JFrog: fix shipped 1 Sep; CVE/blog 14–15 Sep). THN notes Intel Macs cannot install Desktop 27 — those hosts need interim local-account lockdown / vendor guidance. No in-the-wild exploitation reported by JFrog. Primary: JFrog research blog.
- Product
- Parallels Desktop for Mac
- Versions
- Verified vulnerable 26.4.0 (build 57513); treat same-class IPC as in scope until 27.0.0
- Exploited in Australia?
- unknown
- Patch to
- Parallels Desktop 27.0.0+ (Intel Macs: cannot install 27 — apply interim local lockdown per JFrog/vendor)
Primary: JFrog — ParaShells / Parallels Desktop root shell · Vendor: Parallels · CVE: CVE-2026-90894 · The Hacker News — Parallels Desktop (16 Sep 2026)
