ZeroHour

CVE-2026-85146

Hard-coded SSH and Agent Credentials in Lightstar SmartIT Desktop Manager

CVSS 4.0
9.3 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

Lightstar's SmartIT Desktop Manager contains a use of hard-coded credentials flaw (CWE-798), meaning the SSH service account credentials and the passwords for the SmartIT Agent are embedded in the application source code. An unauthenticated remote attacker can obtain these credentials directly from the application source code without any privileges or user interaction. With these valid credentials, an attacker could authenticate to the SSH service and to deployments of the SmartIT Agent, potentially gaining access to affected systems (CVSS 4.0 rates the impact as high across confidentiality, integrity, and availability). Organizations running SmartIT Desktop Manager and its SmartIT Agent component are affected; specific version ranges are not specified in the available advisory data. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.4% probability of exploitation in the next 30 days, so no confirmed exploitation is known.

What to do: Rotate the SSH service account credentials and all SmartIT Agent passwords on systems running SmartIT Desktop Manager, since hard-coded values must be assumed known to attackers. Restrict network access to the SmartIT Desktop Manager and Agent services (e.g., firewall or VPN) and review authentication logs for logins using the exposed accounts. Monitor Lightstar and TWCERT channels for a patched release, as no fixed version is specified in the available data.

Affected
Lightstar SmartIT Desktop Manager (including the SmartIT Agent component)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.

Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.