CVE-2026-18263CWE-749

CVE-2026-18263

High · published August 20, 2026

CVSS v3.0
7.8
EPSS
0%
Percentile
3.1
In the wild
Unconfirmed
What it is

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the RAS RDP Backend Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-28886.

The record
Technical detail
CVSS v3.0
7.8 · HIGH
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00132 · 3.1th percentile
Weakness
CWE-749 · Exposed Dangerous Method or Function
Published
2026-08-20T21:17Z
References (1)
EPSS history
Timeline
  • 20 AUG 16:26Z
    Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability
    cvelistv5