30
55
30
42
35
30
47
60
60
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
CVE-2026-90894 in Parallels Desktop for Mac lets any local user gain root via argument injection; patched in v27.0.0, PoC withheld.
JFrog researchers disclosed CVE-2026-90894, an argument injection flaw in Parallels Desktop for Mac v26.4.0 on Apple silicon that lets any local user gain root on the host. The chain combines a world-writable Unix socket for prl_disp_service (which runs as root), weak peer-credential authentication, and argument injection via --use-compress-program in the appliance extraction tar path. Alludo fixed the flaw in Parallels Desktop v27.0.0 in early September 2026; JFrog published technical details but withheld its proof-of-concept script.
62
47
60
60
60
60
42
55
60
30
30
42
60
47
35
60
60
55
60
47
47
60
55
47
42
30
47
60
60
60
60