Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-85148: SmartIT Desktop Manager allows remote login with fixed password
CVE-2026-85148 · published 21 days ago
Summary
The SmartIT Desktop Manager software includes a password that is built into the program and cannot be changed. Because of this, anyone on the network can connect to computers managed by the tool without providing any credentials, potentially taking control of those machines. Apply any updates released by Lightstar, replace the default password if possible, and limit network access to the manager to trusted systems only.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| lightstar | smartit desktop manager | <= 10 |
Original advisory text
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published4 Sep 2026
Updated25 Sep 2026
First seen4 Sep 2026
Track software like this
Free during beta