CVE-2026-85146
9.8Lightstar · SmartIT Desktop Manager
Lightstar SmartIT Desktop Manager contains a hard-coded credentials vulnerability allowing unauthenticated remote attackers to retrieve SSH service account passwords from the application source code.
Executive summary
Lightstar SmartIT Desktop Manager is vulnerable to a critical hard-coded credential flaw that permits unauthenticated remote attackers to gain unauthorized access via SSH.
Vulnerability
The application suffers from a Use of Hard-coded Credentials (CWE-798) vulnerability. Because the credentials are embedded directly within the source code, any unauthenticated remote attacker can extract valid SSH service account information to compromise the SmartIT Agent.
Business impact
This vulnerability carries a CVSS score of 9.8, reflecting its critical nature and ease of exploitation. Successful exploitation allows an attacker to achieve full administrative control over the SmartIT Agent via SSH, leading to potential unauthorized data access, lateral movement within the network, and complete system compromise.
Remediation
Immediate Action: Update the Lightstar SmartIT Desktop Manager to version 11 or later immediately to remove the hard-coded credentials.
Proactive Monitoring: Review SSH authentication logs for suspicious login attempts or unauthorized access patterns involving the SmartIT Agent service account.
Compensating Controls: Implement strict network segmentation to restrict SSH access to the SmartIT Agent to authorized management subnets only until the update is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents an extreme risk due to the lack of required authentication for exploitation. Security teams should prioritize patching to version 11 or later across all instances of SmartIT Desktop Manager immediately to prevent unauthorized remote access to the environment.