CVE-2026-85146: Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lightstar SmartIT Desktop Managerto a version that resolves this vulnerability.Fixed in 11
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue can be exploited remotely without authentication or user interaction. The attacker can obtain the SmartIT Agent SSH service account credentials and passwords from the application source code.
What access could be gained if the exposed credentials are used?
The disclosed credentials are for the SmartIT Agent's SSH service account. The provided data indicates that exploitation can affect confidentiality, integrity, and availability at a high level.