CVE-2026-85148: Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
Published Sep 4, 2026
·Updated
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
Affected Software
1 affected component
Lightstar SmartIT Desktop Manager
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lightstar SmartIT Desktop Managerto a version that resolves this vulnerability.Fixed in 11
Event History
Sep 4, 2026
CVE Published
via MITRE·02:34 AM
Data Sourced
via MITRE·02:34 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated remote attackers can exploit the fixed password. No prior account or user interaction is required.
2
What access could an attacker gain?
An attacker can use the fixed password to remotely access user hosts managed by the affected software.