Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-85148: SmartIT Desktop Manager allows remote login with fixed password

CVE-2026-85148 · published 21 days ago
Summary

The SmartIT Desktop Manager software includes a password that is built into the program and cannot be changed. Because of this, anyone on the network can connect to computers managed by the tool without providing any credentials, potentially taking control of those machines. Apply any updates released by Lightstar, replace the default password if possible, and limit network access to the manager to trusted systems only.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
lightstar smartit desktop manager <= 10
Original advisory text
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published4 Sep 2026
Updated25 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-85148 · MITRE
Track software like this
Free during beta