CVE-2026-90894 | Parallels Desktop up to 26.4.0/27.0.0 prl_disp_service prl_disp_service.socket PrlSrv_InstallAppliance sVmParentPath os command injection (EUVD-2026-77346)
A vulnerability was found in Parallels Desktop up to 26.4.0/27.0.0. It has been rated as very critical. Affected is the function PrlSrv_InstallAppliance of the file /var/run/prl_disp_service.socket of the component prl_disp_service. This manipulation of the argument sVmParentPath causes os command injection.
This vulnerability is handled as CVE-2026-90894. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.