CVE-2026-90894
Parallels Desktop local privilege escalation via appliance extract argument injection
Description
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Week in review: Cisco patches exploited email gateway 0-day, Revolut breachen-us·Help Net Security·
- Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fixen·The Hacker News· PoC Parallels Desktop for Mac privilege-escalation
- Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)en-us·Help Net Security· PoC Parallels Desktop privilege-escalation
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-90894 and every CVE in our database. Create a free account — no credit card required.
Create Free Account