SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update SmartIT Desktop Manager to version 11 or later.
Workaround
No workaround given by the vendor.
References
History
Fri, 04 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host. | |
| Title | Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-04T02:35:59.531Z
Reserved: 2026-09-03T10:00:27.134Z
Link: CVE-2026-85149
No data.
Status : Received
Published: 2026-09-04T03:17:46.190
Modified: 2026-09-04T03:17:46.190
Link: CVE-2026-85149
No data.
OpenCVE Enrichment
Updated: 2026-09-04T03:30:13Z
Weaknesses