vulnerability
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
HighCVSS 7.8
Summary
Parallels Desktop has a vulnerability (CVE-2026-90894) that allows non-administrator local accounts on Mac computers to gain root access. The flaw stems from a world-writable socket and a process that allows an attacker to build a passwordless sudo rule. While the fix is in Parallels Desktop 27, Intel Macs cannot install this version, and therefore are not protected. The vulnerability is only exploitable on machines running Parallels Desktop 26.4.0 or earlier, and JFrog has not yet confirmed whether the fix will be backported to older versions.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
