Skip to main content
The Wire
CyberNews by Zentrya One
high CVE-2026-90894 Vulnerabilities

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root Access, Leaving Intel Macs Without Confirmed Fix

CVE-2026-90894, dubbed ParaShells, allows non-admin Mac users to exploit Parallels Desktop and execute code as root, while Intel Macs currently lack a confirmed fixed version.

Security researchers have disclosed a high-severity vulnerability in Parallels Desktop for Mac that can allow an ordinary local user—or malicious code already running without administrator privileges—to execute commands as root on the host Mac.

Tracked as CVE-2026-90894 and dubbed ParaShells, the vulnerability was discovered by researchers at JFrog and carries a CVSS score of 7.8.

The flaw affects the macOS host rather than the Windows or Linux virtual machines running inside Parallels.

The situation is particularly significant for organizations still operating Intel-based Macs. JFrog says the relevant security change is present in Parallels Desktop 27, but Parallels Desktop 27 supports only Apple silicon. Intel Macs remain on the version 26 product line, for which no confirmed fix for CVE-2026-90894 has been publicly identified at the time of disclosure.

CVE-2026-90894 at a Glance

Detail Information
CVE CVE-2026-90894
Name ParaShells
Severity High
CVSS 7.8
Product Parallels Desktop for Mac
Vulnerability Local privilege escalation
Required Access Local low-privileged execution
Potential Impact Arbitrary code execution as root
Remote Exploitation No
User Interaction Not required after local execution
Researcher JFrog Security Research
Confirmed Exploitation No known in-the-wild exploitation
Fixed Line Parallels Desktop 27 according to JFrog

How ParaShells Works

Parallels Desktop installs a privileged background component called:

prl_disp_service

The service runs with root privileges because Parallels requires elevated access for operations such as configuring host networking and handling virtual-machine appliances.

JFrog found that unprivileged local processes could communicate with this privileged service through a world-writable Unix socket.

Researchers combined several weaknesses to create the privilege-escalation chain:

World-writable Unix socket

↓

Weak local-client authentication

↓

Attacker communicates with prl_disp_service

↓

Malicious appliance-install request

↓

Argument injection during archive extraction

↓

Attacker-controlled program executed

↓

Program inherits root privileges

↓

Attacker obtains root access

JFrog demonstrated the issue against Parallels Desktop 26.4.0 build 57513 on an Apple silicon Mac.

Abuse of macOS tar Leads to Root Execution

A key part of the exploit involves the mechanism Parallels uses when extracting virtual-machine appliance packages.

JFrog found that attacker-controlled input could influence arguments passed to the macOS tar utility.

Researchers specifically abused the option:

--use-compress-program

This option instructs tar to pass an archive through another program.

Normally, this functionality is legitimate.

The problem is that Parallels' extraction operation is being performed by a service running as root.

As a result, if an attacker can control which program is passed through this option, that program can also execute with root privileges.

In JFrog's proof-of-concept demonstration, the technique was used to create a passwordless sudo configuration and ultimately obtain a root shell.

No Virtual Machine Needs to Be Running

Another important aspect of ParaShells is that exploitation does not require the attacker to compromise a Windows or Linux virtual machine.

In fact, no VM needs to be running at all.

The vulnerability exists in Parallels Desktop's privileged services running on the macOS host.

This means the relevant security boundary is:

Unprivileged macOS process → Root macOS service

rather than:

Guest virtual machine → macOS host

That distinction is important for security teams investigating exposure.

This Is Not a Remote Exploit

CVE-2026-90894 should not be interpreted as allowing an attacker anywhere on the internet to remotely obtain root access to a Mac.

The attacker must first be able to execute code locally as an ordinary user.

However, obtaining low-privileged execution is common in multi-stage attacks.

JFrog gives examples including:

  • Malicious Homebrew packages
  • Compromised npm installation scripts
  • Compromised CI/CD jobs
  • Malicious developer dependencies
  • An attacker controlling a low-privileged local account
  • Shared development, laboratory or training Macs

An attack could therefore look like:

Malicious developer dependency

→ Code executes as normal user

→ ParaShells vulnerability triggered

→ Root privileges obtained

→ Persistence established

→ Credentials or sensitive information accessed

This makes the flaw particularly relevant to developer environments where third-party packages and automated build scripts frequently execute local code.

Why Root Access Matters

Root is effectively the highest privilege level on a macOS system.

Successful privilege escalation could potentially allow an attacker to perform actions unavailable to an ordinary account, including:

  • Modify system files
  • Install persistent malware
  • Create privileged services
  • Access sensitive files
  • Modify security configurations
  • Steal credentials
  • Establish persistence through launchd
  • Tamper with development environments
  • Access data belonging to other local users
  • Deploy additional malicious tools

The exact impact would depend on the system's security configuration and additional macOS protections.

Parallels Desktop 27 Contains the Security Change

JFrog says the relevant change is present in Parallels Desktop 27, listing versions below 27.0.0 as affected.

Parallels Desktop 27.0.0 was released in August 2026, followed by version 27.0.1 build 58670 on September 1.

For Apple silicon users, moving to the latest supported Parallels Desktop 27 release therefore provides the safest remediation path based on currently available information.

However, the situation is considerably more complicated for Intel users.

Intel Macs Cannot Install Parallels Desktop 27

Parallels officially ended Intel Mac support beginning with Parallels Desktop 27.

According to the company:

Parallels Desktop 26 → Intel and Apple silicon

Parallels Desktop 27 → Apple silicon only

Parallels says this transition follows Apple's own platform roadmap, with macOS 26 Tahoe being the final macOS release supporting Intel-based Macs.

Intel Mac users are therefore instructed to remain on the Parallels Desktop 26 product line.

Parallels has stated that version 26 will continue receiving security and maintenance updates for Intel systems.

Latest Version 26 Build Does Not Have JFrog's Confirmed Fix

At the time of disclosure, the latest version available for Intel Macs is:

Parallels Desktop 26.4.2 build 57518

released September 8, 2026.

JFrog says hosts remaining on the 26.x line, including 26.4.2, do not contain the appliance-extraction change that its researchers identify as fixing ParaShells.

This leaves Intel Mac administrators in an unusual situation:

Platform Parallels Version Current Position
Apple silicon Desktop 27.x Security change available
Intel Mac Desktop 26.x No JFrog-confirmed ParaShells fix currently available

Parallels has said Intel users can expect future security and maintenance updates, but no publicly documented version 26 fix specifically addressing CVE-2026-90894 had been identified when the vulnerability was disclosed.

No Evidence of Active Exploitation

JFrog has not reported evidence that CVE-2026-90894 is currently being exploited in real-world attacks.

The vulnerability was discovered through security research rather than investigation of an active campaign.

That distinction is important.

ParaShells provides a potentially valuable post-compromise privilege-escalation technique, but there is currently no public evidence that threat actors are actively using it.

What Organizations Should Do

Organizations using Parallels Desktop should first inventory their Mac fleet and determine:

Apple silicon or Intel?

and:

Which Parallels Desktop version is installed?

Apple silicon systems should be moved to the latest compatible Parallels Desktop 27.x release.

Intel-based systems require additional attention because they cannot install version 27.

Until Parallels provides a confirmed version 26 remediation, organizations should consider reducing opportunities for attackers to obtain the local execution required to exploit the flaw.

Defensive measures include:

  • Restrict unnecessary local user accounts.
  • Remove unused accounts from shared Macs.
  • Limit execution of untrusted software.
  • Review Homebrew and developer-package installation practices.
  • Protect CI/CD build systems.
  • Monitor software-supply-chain dependencies.
  • Maintain strong endpoint protection.
  • Restrict local access to sensitive development systems.
  • Monitor privileged process execution.
  • Watch for unexpected persistence mechanisms.
  • Track future Parallels Desktop 26 security releases.

How Administrators Can Check Exposure

JFrog recommends identifying the installed Parallels version and examining the permissions associated with the dispatcher service socket.

Administrators can check the installed version with:

defaults read "/Applications/Parallels Desktop.app/Contents/Info" CFBundleShortVersionString

and inspect the socket using:

ls -l /var/run/prl_disp_service.socket

JFrog says a socket showing permissions similar to:

srwxrwxrwx

on a build around the vulnerable 26.4.0 configuration should be treated as exposed until a patched build has been confirmed.

These checks indicate potential exposure, not evidence that exploitation has occurred.

Previously Compromised Macs Need Investigation

Updating Parallels Desktop prevents exploitation of the vulnerable path identified by JFrog, but it should not automatically be assumed to remove attacker persistence established before remediation.

Once an attacker obtains root privileges, they may be able to establish other mechanisms for maintaining access.

Security teams investigating a suspected compromise should therefore review:

  • launchd persistence
  • Unexpected LaunchAgents and LaunchDaemons
  • Newly created privileged accounts
  • Suspicious sudo configuration changes
  • Unauthorized SSH keys
  • Recently modified system files
  • Unexpected root-owned processes
  • Suspicious package-manager activity
  • Developer-tool and CI/CD execution history
  • Unusual outbound connections

Where system integrity cannot be confidently established, rebuilding the affected endpoint from a known-clean source may be safer than relying solely on a Parallels update.

Security Takeaway

CVE-2026-90894 demonstrates how a vulnerability in privileged desktop software can turn a relatively limited compromise into complete system control.

An attacker cannot use ParaShells directly over the internet. They first need code execution as an ordinary macOS user.

But once that foothold exists, the vulnerable Parallels service can potentially provide a path from:

Standard User → Root

That makes the flaw particularly relevant for developer workstations, shared Macs and CI/CD environments where third-party packages and scripts frequently execute locally.

The biggest challenge currently affects Intel Mac users.

JFrog identifies Parallels Desktop 27 as containing the relevant security change, while Parallels Desktop 27 cannot be installed on Intel hardware. Parallels says Intel systems will continue receiving version 26 security and maintenance updates, but a specific version 26 fix for CVE-2026-90894 has not yet been publicly confirmed.

Until that changes, organizations should treat vulnerable Intel-based Parallels installations as requiring additional access restrictions, monitoring and risk assessment.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.