Executive brief
SmartIT Desktop Manager is a desktop management application used to manage and maintain user computer systems. CVE-2026-85147 allows unauthenticated attackers to extract a hard-coded password from the application source code and use it to retrieve the AES encryption key used for all communications between the management console and client systems, potentially exposing sensitive administrative traffic and enabling unauthorized system access.
Technical details
This is a use of hard-coded credentials vulnerability in SmartIT Desktop Manager version 10 and earlier. The vulnerability exists because a specific password is embedded in the application source code; unauthenticated remote attackers with access to the application source code can extract this password and leverage it to derive the AES encryption key used to secure communication between the Desktop Manager and its agents. No authentication is required, and the vulnerability is network-accessible. Successful exploitation allows attackers to decrypt and potentially manipulate communications with managed systems. The fix is to update to SmartIT Desktop Manager version 11 or later.
Affected products
- Lightstar SmartIT Desktop Manager 10 and earlier
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: Fix available in version 11 or later