Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-90894] ParaShells: Parallels Desktop Turns Appliance Install Into a Root Shell

Summary

JFrog details CVE-2026-90894 in Parallels Desktop: a world-writable prl_disp_service socket, weak peercred auth, and tar argument injection let unprivileged local users execute code as root.
Published
Collected

original ↗

Related coverage

back