Description
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
Published: 2026-09-04
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SmartIT Desktop Manager contains hard‑coded credentials that unan­uthenticated remote attackers can retrieve from the application or its source code. By extracting this password, an attacker can obtain the AES key used for secure communication, allowing decryption of traffic, impersonation of legitimate clients, or otherwise unauthorized access. The vulnerability reflects an authentication failure weakness (CWE‑284) and compromises the confidentiality and integrity of communications.

Affected Systems

Lightstar SmartIT Desktop Manager is affected. No specific version numbers are listed, so all installations using versions older than 11 could be vulnerable. The vendor recommends upgrading to SmartIT Desktop Manager 11 or later.

Risk and Exploitability

The flaw receives a CVSS score of 8.7, indicating high severity. EPSS data is not available, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is unauthenticated remote access, potentially via an exposed source file or insecure configuration that permits reading the hard‑coded password. Because the exploit does not require privileged access on the target, it could be carried out by a readily available attacker.

Generated by OpenCVE AI on September 4, 2026 at 03:20 UTC.

Remediation

Vendor Solution

Update SmartIT Desktop Manager to version 11 or later.


OpenCVE Recommended Actions

  • Apply the vendor patch: upgrade SmartIT Desktop Manager to version 11 or later.
  • If an immediate upgrade is not possible, restrict filesystem permissions so that the source or credential files cannot be read by unauthenticated users, and remove any exposed source code paths.
  • Configure the application to use strong, unique passwords and secure key management, and disable any legacy authentication mechanisms that rely on hard‑coded credentials.
  • Monitor system logs for unauthorized attempts to read credential files and investigate anomalous access patterns.

Generated by OpenCVE AI on September 4, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
Title Lightstar|SmartIT Desktop Manager - Use of Hard-coded Credentials
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-09-04T02:32:40.277Z

Reserved: 2026-09-03T10:00:25.047Z

Link: CVE-2026-85147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T03:17:45.920

Modified: 2026-09-04T03:17:45.920

Link: CVE-2026-85147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T03:30:13Z

Weaknesses