SmartIT Desktop Manager, developed by Lightstar, contains a Use of Hard-coded Credentials vulnerability identified as CVE-2026-85148. The vulnerability allows unauthenticated remote attackers to exploit a fixed, embedded password to gain unauthorized remote access to user hosts. No authentication is required to leverage this flaw, making it particularly dangerous for affected deployments. The issue is classified as high severity given the ease of exploitation and the potential for full remote access. The vulnerability has been reported via Taiwan CERT (TWCERT) and published on the NVD. Organizations using SmartIT Desktop Manager by Lightstar should apply patches or mitigations immediately. Hard-coded credentials are a well-known and critical class of vulnerability that bypasses standard access controls entirely.