Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85146: SmartIT Desktop Manager lets attackers steal SSH credentials
CVE-2026-85146 · published 21 days ago
Summary
The SmartIT Desktop Manager includes fixed usernames and passwords for its built‑in remote‑login (SSH) feature, and these are visible in the program’s source code. Because anyone on the network can read them, an attacker could obtain the account used by the SmartIT Agent and log into the server. Apply Lightstar’s update or replace the default credentials and restrict network access to the service.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| lightstar | smartit desktop manager | <= 10 |
Original advisory text
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for t...
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published4 Sep 2026
Updated25 Sep 2026
First seen4 Sep 2026
Track software like this
Free during beta