CVE-2026-85149: Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lightstar SmartIT Desktop Managerto a version that resolves this vulnerability.Fixed in 11
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users whose hosts run the SmartIT Agent application are exposed because the disclosed SFTP credentials can be used to browse the host file system remotely.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They need access to the SmartIT Agent source code to obtain the hard-coded SFTP service credentials, then can use those credentials to access the affected host's file system.
What is the documented impact?
The documented impact is unauthorized browsing of the user's host file system through the SmartIT Agent SFTP service. The provided severity vector indicates confidentiality impact only, with no stated integrity or availability impact.