A critical local privilege-escalation flaw, CVE-2026-90894 (“ParaShells”), in Parallels Desktop for Mac allows a standard local user or unprivileged process to execute arbitrary code as root. The vulnerability affects the root-privileged prl_disp_service host daemon and was confirmed in Parallels Desktop 26.4.0 build 57513 on Apple Silicon Macs.
The exploit chain abuses a world-writable Unix socket, insufficient local-client authentication, and tar argument injection during the appliance-installation workflow to turn appliance deployment into a root shell. Parallels fixed the issue in version 27.0.0; organizations should upgrade immediately and consider systems running build 57513 with a world-writable dispatcher socket exposed until remediation is verified.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Parallels remediated CVE-2026-90894 by releasing Parallels Desktop version 27.0.0. Systems using build 57513 with a world-writable prl_disp_service socket were advised to upgrade and be treated as exposed until remediation is verified.
Researchers confirmed CVE-2026-90894 (“ParaShells”) in Parallels Desktop 26.4.0 build 57513 on Apple Silicon Macs. The flaw lets an unprivileged local process connect to the root-run prl_disp_service through a potentially world-writable socket and use tar argument injection during appliance installation to execute code as root.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.