CVE-2026-85148

9.8

Lightstar · SmartIT Desktop Manager

Lightstar SmartIT Desktop Manager contains a hard-coded credentials vulnerability allowing unauthenticated remote attackers to gain unauthorized access to user hosts.

Executive summary

A critical vulnerability in Lightstar SmartIT Desktop Manager allows unauthenticated remote attackers to bypass authentication via hard-coded credentials, posing a severe risk of unauthorized system access.

Vulnerability

The application suffers from a use of hard-coded credentials (CWE-798) vulnerability, which enables an unauthenticated attacker to remotely authenticate to the system using a fixed, static password.

Business impact

Successful exploitation allows an unauthenticated attacker to gain full remote access to user hosts, leading to complete system compromise. With a CVSS score of 9.8, this vulnerability represents an extreme risk of data exfiltration, lateral movement within the network, and total loss of confidentiality, integrity, and availability for affected endpoints.

Remediation

Immediate Action: Update Lightstar SmartIT Desktop Manager to version 11 or later immediately to remove the hard-coded credentials.

Proactive Monitoring: Review system and authentication logs for unauthorized access attempts or logins originating from unusual IP addresses.

Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the management interface until the update is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability is critical due to the ease with which an unauthenticated attacker can gain full control over affected systems. Organizations must prioritize upgrading to version 11 or later to remediate the exposure, as the reliance on hard-coded credentials makes traditional authentication controls ineffective.

More Lightstar CVEs

Sources