Executive brief
SmartIT Desktop Manager is a remote desktop management tool used by system administrators to manage user computers and hosts. This vulnerability allows unauthenticated attackers from the network to gain remote access to managed user systems using a hard-coded password embedded in the application, leading to potential unauthorized system compromise and data theft.
Technical details
CVE-2026-85148 is a Use of Hard-coded Credentials vulnerability in SmartIT Desktop Manager version 10 and earlier. The vulnerability stems from a fixed password hard-coded into the application that can be extracted and leveraged to remotely access user hosts without authentication. The attack vector is network-based with no privileges or user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). An unauthenticated attacker can exploit this to gain unauthorized remote access with high impact to confidentiality, integrity, and availability. The fix is to update to SmartIT Desktop Manager version 11 or later.
Affected products
- Lightstar SmartIT Desktop Manager 10 and earlier
Timeline
- 2026-09-04: disclosed