[CVE-2026-90894] ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell
jfrog.com | vulnerability | CVE-2026-90894 | #privilege-escalation | #lpe | #macos | #vulnerability | #argument-injection | #parallels-desktop | #cve-2026-90894
Summary
JFrog details CVE-2026-90894 in Parallels Desktop: a world-writable prl_disp_service socket, weak peercred auth, and tar argument injection let unprivileged local users execute code as root.
- Published
- Collected
Skip to content