{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/parallels-desktop--27.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:parallels:parallels_desktop:*:*:*:*:*:macos:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-90894"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Parallels Desktop (\u003c 27.0.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","macos","vulnerability","cve-2026-90894"],"_cs_type":"advisory","_cs_vendors":["Parallels"],"content_html":"\u003cp\u003eParallels Desktop for macOS versions prior to 27.0.0 contain a critical local privilege escalation (LPE) vulnerability tracked as CVE-2026-90894. The flaw exists within the 'prl_disp_service', a background service running with root privileges that exposes a world-writable socket to local users. An attacker can interact with this socket to trigger an appliance installation process.\u003c/p\u003e\n\u003cp\u003eThe service implements an insecure re-tokenization mechanism when executing 'tar' or 'bsdtar' for archive extraction. By providing a malicious archive name containing additional tar flags, an attacker can perform argument injection. This allows the execution of arbitrary commands as root, most notably through the '--use-compress-program' flag, which can point to an attacker-controlled file residing in a user-writable directory like /tmp. Successful exploitation grants the attacker full root access to the host system.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes local access on the target macOS host as a standard user.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the world-writable IPC socket exposed by 'prl_disp_service'.\u003c/li\u003e\n\u003cli\u003eAttacker sends a malformed request to the service to trigger the appliance installation routine.\u003c/li\u003e\n\u003cli\u003eThe service constructs a command string incorporating an attacker-provided archive folder name.\u003c/li\u003e\n\u003cli\u003eThe attacker-supplied name injects malicious arguments, specifically '--use-compress-program', into the command string.\u003c/li\u003e\n\u003cli\u003e'prl_disp_service' executes 'tar' or 'bsdtar' with the injected flags running as root.\u003c/li\u003e\n\u003cli\u003e'tar' spawns the specified external program defined in the injected argument, executing it with root privileges.\u003c/li\u003e\n\u003cli\u003eAttacker gains full root control over the system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-90894 allows any local unprivileged user on a macOS system to elevate privileges to root. This impacts all Parallels Desktop installations on macOS prior to version 27.0.0. The ability to execute arbitrary code as root provides an attacker with complete control over the host, enabling data exfiltration, installation of persistence mechanisms, and bypassing of macOS security controls.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Parallels Desktop to version 27.0.0 or later immediately to address CVE-2026-90894.\u003c/li\u003e\n\u003cli\u003eFor hosts that cannot be upgraded, restrict local login access as an interim control, as the dispatcher socket is reachable by any local account.\u003c/li\u003e\n\u003cli\u003eDeploy the provided detection logic to identify 'prl_disp_service' spawning 'tar' or 'bsdtar' with an anomalous number of arguments.\u003c/li\u003e\n\u003cli\u003eInvestigate any child processes spawned by 'tar' or 'bsdtar' that originate from 'prl_disp_service', especially those referencing paths in /tmp or /var/tmp.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T10:10:22Z","date_published":"2026-09-28T10:10:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-parallels-pe/","summary":"Parallels Desktop versions prior to 27.0.0 are vulnerable to local privilege escalation via an argument injection flaw in the root-privileged prl_disp_service.","title":"Local Privilege Escalation in Parallels Desktop via Argument Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-parallels-pe/"}],"language":"en","title":"CraftedSignal Threat Feed - Parallels Desktop (\u003c 27.0.0)","version":"https://jsonfeed.org/version/1.1"}