CVE-2026-85149 Details
Description
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
A vulnerability allowing the use of hard-coded credentials has been identified in Lightstar's SmartIT Desktop Manager, specifically in versions through 10. This vulnerability allows unauthenticated remote attackers to access SFTP service credentials for the SmartIT Agent application by extracting them from the source code. With these credentials, attackers can browse the file system of the user's host.
Users are advised to update SmartIT Desktop Manager to version 11 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.twcert.org.tw/en/cp-139-11177-13ca3-2.html | [email protected] | AdvisoryBundleRemedy |
| https://www.twcert.org.tw/tw/cp-132-11176-a4cc2-1.html | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lightstar SmartIT Desktop Manager | <= 10 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion