← Terug naar overzicht

SmartIT Desktop Manager, developed by Lightstar, contains a Use of Hard-coded Credentials vulnerability identified as CVE-2026-85146. The flaw allows unauthenticated remote attackers to extract SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. No authentication is required to exploit this vulnerability, making it particularly dangerous. The exposure of hard-coded credentials in source code represents a critical security risk, as attackers can gain unauthorized SSH access to managed systems. This vulnerability is catalogued by both NVD (NIST) and TWCERT, indicating formal recognition by cybersecurity authorities. The impact is rated High, as successful exploitation could lead to full compromise of systems managed by the SmartIT Agent. Organizations using SmartIT Desktop Manager by Lightstar should apply patches or mitigations immediately and rotate any exposed credentials.

Affected products

  • SmartIT Agent
  • SmartIT Desktop Manager

Related CVE's

  • CVE-2026-85146

Categories

  • Enterprise Applications
  • Identity & Access