Junglewise Threat Intelligence

CVE-2026-85148: Lightstar SmartIT Desktop Manager hard-coded credentials in remote access

CVE-2026-85148 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Technologies: Lightstar SmartIT Desktop Manager. Vendors: Lightstar.

Executive brief

SmartIT Desktop Manager is a remote desktop management tool used by system administrators to manage user computers and hosts. This vulnerability allows unauthenticated attackers from the network to gain remote access to managed user systems using a hard-coded password embedded in the application, leading to potential unauthorized system compromise and data theft.

Technical details

CVE-2026-85148 is a Use of Hard-coded Credentials vulnerability in SmartIT Desktop Manager version 10 and earlier. The vulnerability stems from a fixed password hard-coded into the application that can be extracted and leveraged to remotely access user hosts without authentication. The attack vector is network-based with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). An unauthenticated attacker can exploit this to gain unauthorized remote access with high impact to confidentiality, integrity, and availability. The fix is to update to SmartIT Desktop Manager version 11 or later.

Affected products

  • Lightstar SmartIT Desktop Manager 10 and earlier

Timeline

  • 2026-09-04: disclosed

References

Related threats