Description
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update SmartIT Desktop Manager to version 11 or later.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 04 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code. | |
| Title | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-04T02:31:41.627Z
Reserved: 2026-09-03T10:00:23.564Z
Link: CVE-2026-85146
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
