CVE-2026-85147: Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
Published Sep 4, 2026
·Updated
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
Affected Software
1 affected component
Lightstar SmartIT Desktop Manager
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lightstar SmartIT Desktop Managerto a version that resolves this vulnerability.Fixed in 11
Event History
Sep 4, 2026
CVE Published
via MITRE·02:32 AM
Data Sourced
via MITRE·02:32 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated remote attackers can exploit it. The attack does not require prior privileges or user interaction.
2
What can an attacker obtain through exploitation?
An attacker can obtain a specific password from the source code and use it to retrieve the AES encryption key used for communication.