Local Privilege Escalation in Parallels Desktop via Argument Injection
Parallels Desktop versions prior to 27.0.0 are vulnerable to local privilege escalation via an argument injection flaw in the root-privileged prl_disp_service.
CVE search metadata
CVE search record: CVE-2026-90894. Severity: high. CVSS: 7.8. EPSS: 0.17%. KEV: no. Product: Parallels Desktop (< 27.0.0). Brief: Local Privilege Escalation in Parallels Desktop via Argument Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-09-parallels-pe/
Parallels Desktop for macOS versions prior to 27.0.0 contain a critical local privilege escalation (LPE) vulnerability tracked as CVE-2026-90894. The flaw exists within the 'prl_disp_service', a background service running with root privileges that exposes a world-writable socket to local users. An attacker can interact with this socket to trigger an appliance installation process.
The service implements an insecure re-tokenization mechanism when executing 'tar' or 'bsdtar' for archive extraction. By providing a malicious archive name containing additional tar flags, an attacker can perform argument injection. This allows the execution of arbitrary commands as root, most notably through the '--use-compress-program' flag, which can point to an attacker-controlled file residing in a user-writable directory like /tmp. Successful exploitation grants the attacker full root access to the host system.
Attack Chain
- Attacker establishes local access on the target macOS host as a standard user.
- Attacker interacts with the world-writable IPC socket exposed by 'prl_disp_service'.
- Attacker sends a malformed request to the service to trigger the appliance installation routine.
- The service constructs a command string incorporating an attacker-provided archive folder name.
- The attacker-supplied name injects malicious arguments, specifically '--use-compress-program', into the command string.
- 'prl_disp_service' executes 'tar' or 'bsdtar' with the injected flags running as root.
- 'tar' spawns the specified external program defined in the injected argument, executing it with root privileges.
- Attacker gains full root control over the system.
Impact
Successful exploitation of CVE-2026-90894 allows any local unprivileged user on a macOS system to elevate privileges to root. This impacts all Parallels Desktop installations on macOS prior to version 27.0.0. The ability to execute arbitrary code as root provides an attacker with complete control over the host, enabling data exfiltration, installation of persistence mechanisms, and bypassing of macOS security controls.
Recommendation
- Upgrade Parallels Desktop to version 27.0.0 or later immediately to address CVE-2026-90894.
- For hosts that cannot be upgraded, restrict local login access as an interim control, as the dispatcher socket is reachable by any local account.
- Deploy the provided detection logic to identify 'prl_disp_service' spawning 'tar' or 'bsdtar' with an anomalous number of arguments.
- Investigate any child processes spawned by 'tar' or 'bsdtar' that originate from 'prl_disp_service', especially those referencing paths in /tmp or /var/tmp.
Immediate actions
Upgrade Parallels Desktop to 27.0.0 or later
Mitigations
Restrict local login access on affected macOS hosts
CVE-2026-90894
Detection coverage 1
Detect CVE-2026-90894 Exploitation - Parallels Appliance Extract Argument Injection
highDetects prl_disp_service spawning tar/bsdtar with an excessive number of arguments, indicating potential argument injection for privilege escalation.
Detection queries are available on the platform. Get full rules →