Parallels RAS Client Vulnerability Allows Local Privilege Escalation
A local privilege escalation vulnerability (CVE-2026-13121) in Parallels RAS Client's RDP backend service allows attackers with initial low-privileged code execution to gain SYSTEM privileges.

A critical local privilege escalation vulnerability, identified as CVE-2026-13121, has been disclosed in Parallels RAS Client's RDP backend service. This flaw allows an attacker who has already gained the ability to execute low-privileged code on a target system to escalate their privileges to the highest level, effectively gaining SYSTEM privileges.
The vulnerability stems from an exposed dangerous function within the RAS RDP Backend Service. By leveraging this function, an attacker can execute arbitrary code in the context of the SYSTEM account. This level of access would permit an attacker to perform a wide range of malicious activities, including installing programs, viewing, altering, or deleting data, and creating new accounts with full user rights.
The Zero Day Initiative (ZDI), which published the advisory, assigned this vulnerability a CVSS score of 7.8, indicating a high severity. While the exploit requires initial local code execution, the ability to achieve SYSTEM privileges significantly amplifies the potential impact on affected organizations.
Parallels has addressed this vulnerability by releasing version 21.2 of its RAS Client. Users are strongly advised to update to this latest version to mitigate the risk associated with CVE-2026-13121. Further details on the fix can be found in Parallels' knowledge base article KB131037.
The vulnerability was initially reported to the vendor on February 25, 2026. Following a coordinated disclosure process, the advisory was publicly released on August 11, 2026, with an update to the advisory also published on the same day. The research leading to the discovery of this flaw is credited to khongtrang.
This discovery highlights the ongoing threat posed by privilege escalation vulnerabilities, particularly in remote access and desktop infrastructure. Such flaws can be a crucial step for attackers seeking to move laterally within a network or gain deeper control over compromised systems after an initial foothold has been established.
Organizations utilizing Parallels RAS Client should prioritize patching this vulnerability to prevent potential exploitation. The requirement for initial local access means that defenses against initial compromise, such as endpoint security and user awareness training, remain critical layers of security.
The Zero Day Initiative advisory ZDI-26-556 provides further details on the local privilege escalation vulnerability affecting Parallels RAS Client's RDP backend service. This advisory assigns the vulnerability a CVSS score of 7.8 and confirms it is fixed in version 21.2, with the disclosure timeline indicating a coordinated public release on August 11, 2026.
This advisory updates the initial report by providing the specific CVE identifier, CVE-2026-18262, and details that the vulnerability is fixed in version 21.2 of Parallels RAS Client, as noted in their knowledge base article. The Zero Day Initiative has assigned this vulnerability a CVSS score of 7.8, highlighting its significant severity.