A significant local privilege escalation (LPE) vulnerability has been disclosed in Parallels Desktop for Mac, a popular virtualization software. The flaw, nicknamed "ParaShells" and tracked as CVE-2026-90894, allows a local user with standard, non-administrative privileges to gain full root access on the host macOS system. The vulnerability was discovered by a researcher from JFrog and reported to Parallels' parent company, Alludo. A patch has been released, and given the publication of technical details, immediate updates are recommended.
The "ParaShells" vulnerability is a local privilege escalation flaw. It stems from a weakness in how Parallels Desktop handles certain operations, allowing a low-privileged local user to bypass standard macOS security controls. By exploiting this weakness, a user who should be restricted to their own account can execute code with the privileges of the root user, granting them complete control over the entire machine. This type of vulnerability is especially dangerous in multi-user environments such as university labs, corporate shared workstations, or any system with multiple user accounts.
The vulnerability was patched in Parallels Desktop v27.0.0, released in early September 2026. The technical details of the flaw were publicly disclosed by the discovering researcher on September 16, 2026. While a full proof-of-concept (PoC) exploit script was withheld to prevent immediate widespread abuse, the detailed write-up provides a clear path for knowledgeable attackers to develop their own exploit.
The impact of CVE-2026-90894 is severe for affected systems. An attacker who has already gained initial access to a Mac with a low-privilege account (e.g., through phishing or malware) can use this vulnerability to:
In a shared environment, one compromised standard account can lead to the compromise of the entire system and all data on it.
Detecting exploitation of LPE vulnerabilities often involves looking for anomalous process behavior. The following patterns may help identify related activity:
root privileges outside of normal installation or update routines.sudo commands executed by unexpected user accounts/etc/ or /private/.Updating Parallels Desktop to the patched version is the only way to remediate the vulnerability.
Limiting the number of local accounts on a system reduces the attack surface for local privilege escalation flaws.
Parallels Desktop v27.0.0 is released, patching CVE-2026-90894.
Technical details of the 'ParaShells' vulnerability are publicly disclosed.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.