CVE Tools
Back to feed
PoC public Parallels Desktop privilege-escalation Parallels

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Help Net Security·By Zeljka Zorz··2 min read
CVE Tools coverage

A public proof of concept has highlighted CVE-2026-90894, also known as ParaShells, an argument injection issue in Parallels Desktop for Mac v26.4.0 on Apple ARM-based macOS systems. A low-privileged local user can abuse the root-running prl_disp_service to obtain root access, potentially exposing other users' data and enabling persistence; Parallels fixed the flaw in Parallels Desktop v27.0.0, so organizations should upgrade.