CVE-2026-85149
Received Received - Intake

Use of Hard-coded Credentials in SmartIT Desktop Manager

Vulnerability report for CVE-2026-85149, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: TWCERT/CC

Description

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-04
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
lightstar smartit_desktop_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SmartIT Desktop Manager by Lightstar has a hard-coded credentials vulnerability. Unauthenticated remote attackers can extract the SFTP service credentials from the application's source code and gain access to the user's file system.

Detection Guidance

Check SmartIT Desktop Manager source code or installed files for hard-coded SFTP credentials. Search for strings like 'password', 'credential', or 'SFTP' in configuration files or binaries. Use tools like grep or strings to inspect application files and logs for unusual SFTP access attempts.

Impact Analysis

Attackers could access sensitive files on your system without authentication. This may lead to data theft, unauthorized modifications, or further exploitation of your network.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data. GDPR may require breach notification, while HIPAA could impose penalties for unauthorized access to protected health information.

Mitigation Strategies

Update SmartIT Desktop Manager to the latest patched version if available. Remove any hard-coded credentials from the application and use secure credential storage. Restrict network access to the SFTP service and monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85149. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart