Executive brief
SmartIT Desktop Manager is an IT administration tool used to manage remote endpoints and host systems. The software contains multiple hard-coded credentials embedded in its source code, allowing attackers to extract SSH, SFTP, and encryption key passwords without authentication. An attacker with access to the application code can obtain full remote access to user systems, extract sensitive files, and intercept encrypted communications.
Technical details
The vulnerability is a use of hard-coded credentials flaw affecting SmartIT Desktop Manager versions 10 and earlier. Unauthenticated remote attackers can extract SSH service account credentials (CVE-2026-85146), AES encryption key passwords (CVE-2026-85147), fixed remote access passwords (CVE-2026-85148), and SFTP credentials (CVE-2026-85149) directly from the application source code. The attack vector is network-based with no authentication or user interaction required. Exploitation allows attackers to gain remote access to managed hosts, retrieve encryption keys for communication interception, and browse host file systems. The vendor has released version 11 and later with fixes.
Affected products
- Lightstar SmartIT Desktop Manager 10 and earlier
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: Fix available in version 11 and later