CVE-2026-85148
9.8Lightstar · SmartIT Desktop Manager
Lightstar SmartIT Desktop Manager contains a hard-coded credentials vulnerability allowing unauthenticated remote attackers to gain unauthorized access to user hosts.
Executive summary
A critical vulnerability in Lightstar SmartIT Desktop Manager allows unauthenticated remote attackers to bypass authentication via hard-coded credentials, posing a severe risk of unauthorized system access.
Vulnerability
The application suffers from a use of hard-coded credentials (CWE-798) vulnerability, which enables an unauthenticated attacker to remotely authenticate to the system using a fixed, static password.
Business impact
Successful exploitation allows an unauthenticated attacker to gain full remote access to user hosts, leading to complete system compromise. With a CVSS score of 9.8, this vulnerability represents an extreme risk of data exfiltration, lateral movement within the network, and total loss of confidentiality, integrity, and availability for affected endpoints.
Remediation
Immediate Action: Update Lightstar SmartIT Desktop Manager to version 11 or later immediately to remove the hard-coded credentials.
Proactive Monitoring: Review system and authentication logs for unauthorized access attempts or logins originating from unusual IP addresses.
Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the management interface until the update is applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability is critical due to the ease with which an unauthenticated attacker can gain full control over affected systems. Organizations must prioritize upgrading to version 11 or later to remediate the exposure, as the reliance on hard-coded credentials makes traditional authentication controls ineffective.