Description
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group.



After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.
Published: 2026-09-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Immediate Patch
AI Analysis

Impact

Parallels Desktop hosts a root‑privileged daemon, prl_disp_service, that listens on a world‑writable Unix socket. The service accepts local login requests and allows untrusted users to specify the path of an appliance to install. The daemon constructs a tar command using the supplied path without proper sanitization; a quote in the path causes the command string to be split incorrectly, allowing an attacker to inject unintended tar options. Because macOS’s tar can execute a specified compression program as root, the attacker can run arbitrary commands with root privileges whenever a local user requests an appliance extraction.

Affected Systems

Products affected are Parallels Desktop for Mac. The vulnerability exists before the release of Parallels Desktop 27.0.0, which contains the fix.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity local exploitation scenario. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of a KEV listing does not preclude active attacks. The attack vector is local; any user who can run the Parallels client can trigger the vulnerable routine and obtain root privileges on the host. The vulnerability stems from improper with elevated rights (CWE‑78), and command injection via arbitrary filesystem paths (CWE‑88).

Generated by OpenCVE AI on September 15, 2026 at 14:43 UTC.

Remediation

Vendor Solution

Upgrade to Parallels Desktop 27.0.0 or later.


OpenCVE Recommended Actions

  • Upgrade Parallels Desktop to version 27.0.0 or later, which removes the unvalidated tar invocation.
  • Reconfigure or restrict the socket file /var/run/prl_disp_service.socket so it is not world‑writable; set ownership to root and permissions to 600.
  • Limit appliance extraction functionality to trusted users only, and disable automatic extraction features if not required until the update is installed.
  • As a temporary safeguard, monitor or block execution of tar commands from the Parrelabs service, or use an App Control policy to prevent the service from running arbitrary binaries.

Generated by OpenCVE AI on September 15, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.
Title Parallels Desktop local privilege escalation via appliance extract argument injection
Weaknesses CWE-269
CWE-78
CWE-88
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published:

Updated: 2026-09-15T08:49:26.122Z

Reserved: 2026-09-14T09:33:11.942Z

Link: CVE-2026-90894

cve-icon Vulnrichment

Updated: 2026-09-14T10:23:41.733Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T10:17:06.133

Modified: 2026-09-18T19:31:11.370

Link: CVE-2026-90894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:45:11Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-88

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')