CVE-2026-90894 Parallels Desktop for Mac update: who needs 27.0.0 or later
CVE-2026-90894 is a local privilege-escalation flaw in Parallels Desktop for Mac. Here is the verified update path and the Intel and Ventura constraint.

- CVE-2026-90894 is a host-side local privilege-escalation issue: JFrog demonstrated a non-admin local user reaching root on Parallels Desktop 26.4.0 (build 57513) on Apple silicon.
- The CVE Program identifies 26.4.0 as affected and 27.0.0 as unaffected. JFrog describes versions below 27.0.0 as affected, but did not regression-test every older build.
- Parallels Desktop 27.0.0 is build 58628 and 27.0.1 is build 58670. Eligible systems should move to 27.0.0 or later through normal change controls, not by testing an exploit.
- Desktop 27 requires Apple silicon and excludes macOS Ventura 13. Intel Macs and Ventura hosts cannot use that upgrade path; the reviewed public material does not name a 26.x CVE-2026-90894 fix.
- The published CVSS 3.1 score is 7.8 High from CNA JFrog. NVD had not supplied its own score at the research cutoff, and no reviewed source reported active exploitation.
CVE-2026-90894 is a local Mac privilege boundary problem
CVE-2026-90894 Parallels Desktop is a security issue in the Mac host application, not a flaw reported inside a Windows or Linux guest. JFrog Security Research, which is the CNA named on the public CVE record, says it demonstrated a standard, non-administrator local macOS user causing code to run with root privileges on Parallels Desktop 26.4.0, build 57513, on Apple silicon. Root is the system account with broad control over the Mac. A local privilege escalation, or LPE, is a flaw that lets a process already running on a device obtain more authority than it should have.
That distinction sets the response priority accurately. The documented vector is local: JFrog says its laboratory chain needed a low-privilege account or process on a vulnerable Mac, the privileged Parallels helper service and its normal local communication path. It did not require a running virtual machine, an elevated Parallels role or a Parallels-signed client. The CVSS 3.1 score published by CNA JFrog is 7.8, High, with local attack vector and low privileges required. NVD displays that CNA score but says its own assessment is not yet provided.
Exposure is therefore not the same as exploitation. The evidence supports checking a Mac where an untrusted local process could run, shared or lightly controlled user accounts exist, or another compromise might already have created a local foothold. It does not show that an attacker can directly reach a Mac over the internet through this CVE. It also does not show active exploitation: none of the reviewed public sources makes that claim.
What the public record establishes about the affected versions
The cleanest fixed-version boundary in the public record is 27.0.0. The CVE Program lists Parallels Desktop for Mac on macOS, identifies 26.4.0 as affected, and identifies 27.0.0 as unaffected. JFrog’s vulnerability notice likewise directs administrators to upgrade to Parallels Desktop 27.0.0 or later. Parallels’ current release summary identifies 27.0.0 as build 58628 and 27.0.1 as build 58670. The vendor dates 27.0.0 to 25 August 2026 and 27.0.1 to 1 September 2026.
Precision matters on the older line. JFrog’s notice describes affected versions as earlier than 27.0.0 and says that 26.4.2 did not include the relevant extraction change. But its fuller research post says it did not regression-test every older build. The CVE record itself names 26.4.0 rather than publishing a complete historical version matrix. It is fair to treat a 26.x installation as requiring assessment against the documented 27.0.0 threshold; it is not fair to say every release before 27 was individually proven in a lab.
There is another uncertainty administrators should preserve in their records. Parallels’ public Desktop 26 release notes list 26.4.2, build 57518, dated 8 September, but do not name CVE-2026-90894. The reviewed vendor security-updates table also does not yet list this CVE. That is not evidence that 26.4.2 fixes it. On the evidence available at the cutoff, only 27.0.0 or later is the documented fixed destination.
The technical scope, without turning it into a test recipe
JFrog attributes the weakness to how the root-running prl_disp_service helper handled part of the appliance-install process. A privileged helper is a background service that carries out operations needing higher rights than an ordinary user has. The researcher says unsafe handling of an externally influenced installation path could change the arguments supplied to a system archive tool. In the tested condition, that let a low-privilege local user cross the host’s privilege boundary.
The public CVE record classifies the underlying issues as improper privilege management, OS command neutralisation and argument injection. Those labels explain why the impact can be severe even when the initial access is limited. They do not turn this into a remote-network vulnerability or mean an ordinary virtual machine is inherently unsafe. The reported chain ran on the Mac host and was tied to a Parallels service, not a guest operating system escaping by itself.
Reddy News is not reproducing crafted input, commands, files or proof-of-concept steps. They are unnecessary for a useful administrative decision and could enable misuse. A safer operational question is whether the affected product, hardware and host operating-system combination exists in the fleet, and whether someone with local access could use an untrusted process before the version boundary is reached.
Upgrade eligible Apple-silicon Macs to 27.0.0 or later
For an Apple-silicon Mac that meets Desktop 27’s host requirements, the remediation path is straightforward in principle: upgrade Parallels Desktop to 27.0.0 or later. Parallels’ published in-product route is the Parallels Desktop menu followed by Check for Updates. It also provides a manual download path. Before a broad rollout, record each host’s product edition, installed version and build, macOS release, chip type, virtual-machine dependencies and whether an MDM policy controls updates. Keep the organisation’s normal VM backup, maintenance-window and recovery controls in place.
Version 27 has a useful current target beyond the initial fixed release. Parallels lists 27.0.1 (58670) as a subsequent update that addresses overall stability and security issues. Administrators do not need to stop at 27.0.0 if the later release is approved for their environment; the important public boundary for this CVE is at least 27.0.0. This article does not claim that all unrelated stability or compatibility risks disappear after the update, so normal pilot testing remains appropriate.
After installation, use the product’s About information or the endpoint-management inventory to confirm the version and build rather than relying only on a completed installer. Then verify ordinary outcomes that matter locally: Parallels Desktop starts, required virtual machines open, expected guest connectivity works, and managed settings remain applied. Do not use an exploit demonstration as a verification test.
Intel and macOS Ventura systems cannot take the version 27 path
The compatibility constraint is not a footnote. Parallels says Desktop 27 requires a Mac with Apple silicon. Its Desktop 27 release notes also say support for Intel Macs and installation on macOS Ventura 13 were removed. Current system requirements list macOS Sonoma 14.7, Sequoia 15.5, Tahoe 26 and Golden Gate 27 when released as the host range for version 27; on earlier operating systems including Ventura 13, the installer sets up an earlier supported product version instead.
This means an Intel Mac cannot be remediated by forcing Desktop 27 onto the device, and a Ventura host cannot be declared fixed merely because it runs the latest 26.x release. Parallels says it will continue security and maintenance updates for Desktop 26 on Intel hardware, which is important support context. But the reviewed public documents do not identify a Desktop 26 build that fixes CVE-2026-90894. A device owner needs a CVE-specific answer from Parallels before recording that legacy line as remediated.
Until that answer and a viable platform plan exist, JFrog’s public interim mitigation is to restrict local login on Macs with vulnerable installations. In practical terms, administrators should identify the affected group, reduce unnecessary local account access in accordance with policy, and consider the risk of untrusted local processes. That is a temporary exposure reduction, not a substitute for a confirmed fixed build. It should be paired with host operating-system updates and normal endpoint controls, not presented as a cure.
Managed Business and Enterprise deployments need a rollout check
Managed editions add two deployment questions: is the appropriate update actually available to the device group, and does policy permit a major-version upgrade? Parallels says updates for Business and Enterprise editions can be delayed by one to two weeks after their public release. Its current table lists 27.0.1 for Apple-silicon managed systems and 26.4.2 for Intel managed systems, both with their stated September availability. It also says an IT administrator can disable major upgrades.
That makes inventory evidence more valuable than a generic statement that every Mac is ‘up to date’. Split reports by Apple silicon versus Intel, host macOS, Desktop version/build and edition. Review MDM scoping before deployment: an automatic policy aimed at 27 must not be sent to Intel hardware, and it cannot solve a Ventura 13 compatibility block. A pilot group can test guest workloads, endpoint policies and recovery steps before a phased rollout.
For the legacy segment, escalation should be explicit. Document that current vendor materials support Desktop 26 on Intel but do not publicly name a CVE-2026-90894 fixed 26.x release. Ask Parallels support for a supported remediation route, then update the risk record when a source identifies one. Reusing an old release-note phrase such as ‘stability and security issues’ as evidence of this particular patch would be unsupported.
Post-update verification should prove the version, not reproduce the flaw
A good completion record contains more than a help-desk ticket. Keep the device identifier, chip family, macOS release, Parallels edition, pre-change version, post-change version/build, update date, operator and normal-service checks. For eligible devices, the desired recorded state is 27.0.0 (58628) or a later approved 27.x build such as 27.0.1 (58670). This creates a clear audit boundary if future advisories revise the product matrix.
Check the host and the virtual-machine workflow separately. This CVE concerns a host-side Parallels helper, while Parallels itself advises applying macOS security updates and separately keeping guest operating systems updated. Updating the application does not replace macOS updates, and a current host does not automatically make an old guest operating system secure. Conversely, guest patching alone is not a substitute for reaching the Desktop fixed version.
No retained source supplies a safe public diagnostic that conclusively proves the vulnerable behaviour is absent beyond confirming the fixed product version. That is a sensible boundary. Administrators should not create hostile local test conditions or run public proof-of-concept material in production. If there is evidence of suspicious local activity, preserve relevant organisational evidence and use the organisation’s incident-response process; this article does not infer that a particular Mac has been compromised.
What remains unverified at the 16 September cutoff
Several conclusions are deliberately not drawn. The public sources reviewed do not say CVE-2026-90894 is being actively exploited, identify an attacker or victim, state a campaign size, or provide a vendor-published 26.x fix. JFrog’s research was demonstrated on Apple silicon with 26.4.0. It says the App Store Edition may differ in how services start, so this article does not classify that edition as affected or unaffected. It also does not convert the researcher’s description of versions below 27 into a claim that every historical build was tested.
The score should also be read accurately. The 7.8 High rating and CVSS vector come from JFrog as the CNA. NVD mirrors the record but had not issued an NVD assessment by the cutoff. That is enough to explain the severity signal, but it is not an independently calculated NIST score. The responsible next step is to recheck Parallels’ current release and security documentation before approving a fleet-wide change, because version information can change.
For Parallels administrators, the actionable conclusion is narrower: identify exposed local hosts, move compatible Apple-silicon systems to 27.0.0 or later, keep Intel and Ventura systems in a separately tracked risk group, and do not overstate what the public record has verified.
Reader guide
Article questions, answered
Short answers to common reader questions based on the reporting above.
What is CVE-2026-90894 in Parallels Desktop for Mac?
CVE-2026-90894 is a local privilege-escalation vulnerability in Parallels Desktop for Mac. JFrog, the CNA for this record, says a non-administrator local user could cause code to run as root through the product’s appliance-install handling on its tested 26.4.0 build. Root is the macOS account with broad system control. The CVE Program lists 26.4.0 as affected and 27.0.0 as unaffected. It is not a report of a remotely reachable Parallels Desktop flaw.
Which Parallels Desktop versions need attention for CVE-2026-90894?
The public record specifically marks Parallels Desktop 26.4.0 as affected and 27.0.0 as unaffected. JFrog’s vulnerability page describes versions below 27.0.0 as affected and says 26.4.2 does not contain the relevant corrective change, but it also says it did not regression-test every earlier build. Treat 27.0.0 or later as the documented fixed threshold. Do not claim that every historical build was lab-tested, and do not assume the latest 26.x build fixes this CVE.
Can CVE-2026-90894 be exploited remotely?
The documented attack vector is local. JFrog’s proof required a low-privilege local macOS user or process on a vulnerable host; it did not require a running virtual machine, Parallels administrator status or a signed Parallels client. That makes the flaw serious after local access is obtained, but it is not evidence that an internet attacker can directly compromise a Mac through this CVE. The sources reviewed for this article do not state that it is under active exploitation.
Can an Intel Mac or a Mac on macOS Ventura install Parallels Desktop 27?
No. Parallels says Desktop 27 requires Apple silicon and does not support installation on macOS Ventura 13. Its published requirements begin with macOS Sonoma 14.7 for the relevant older supported host release. Intel Macs remain on Desktop 26, for which Parallels says security and maintenance updates will continue. However, the reviewed vendor material does not identify a 26.x build that fixes CVE-2026-90894, so an Intel- or Ventura-bound fleet should obtain CVE-specific guidance rather than declare itself remediated.
How should an administrator verify the Parallels Desktop update?
After the approved update, record the version and build shown in Parallels Desktop’s About information or in the organisation’s endpoint-management inventory. Parallels lists 27.0.0 as build 58628 and 27.0.1 as build 58670. Confirm that ordinary virtual-machine start-up, required guest connectivity and managed policies work under the organisation’s change controls. A public proof-of-concept should not be used as a production verification test.
Sources and further reading
These references support the factual context used in this article. Links open the original publisher.
- Parallels Desktop 27 updates summaryParallels · accessed 16 September 2026
- Parallels Desktop for Mac System RequirementsParallels · accessed 16 September 2026
- Parallels Desktop compatibility with Intel-based Mac computersParallels · accessed 16 September 2026
- Parallels Desktop 26 updates summaryParallels · accessed 16 September 2026
- Update availability for Parallels Desktop Business and Enterprise EditionsParallels · accessed 16 September 2026
- CVE-2026-90894CVE Program · accessed 16 September 2026
- CVE-2026-90894 DetailNational Vulnerability Database · accessed 16 September 2026
- Parallels Desktop is vulnerable to a Local Privilege Escalation via Appliance Extract Argument InjectionJFrog Security Research · accessed 16 September 2026
- ParaShells: Parallels Desktop Turns Appliance Install Into a Root ShellJFrog · accessed 16 September 2026