Use of Hard-coded Credentials in SmartIT Desktop Manager by Lightstar
CVE-2026-85146

9.3CRITICAL

Key Information:

Vendor

Lightstar

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85146?

The SmartIT Desktop Manager by Lightstar contains a vulnerability that exposes hard-coded credentials within the application source code. This issue allows unauthenticated remote attackers to access sensitive SSH service account credentials and passwords used by the SmartIT Agent. If exploited, this could lead to unauthorized access and control over systems running the affected version of the application. Users and administrators are advised to review their security practices and apply any available updates from the vendor.

Affected Version(s)

SmartIT Desktop Manager 0 <= 10

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.