CVE Feed

    Dashboard / CVE / CVE-2026-85149

    CVE-2026-85149

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.

    Published:Sep 4, 2026
    Last Modified:Sep 4, 2026
    EPS:Sep 4, 2026
    EPSS Score:0.00249
    CVSS Score:5.3

    Affected Products

    Vendor
    Lightstar
    Product
    Smartit Desktop Manager

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High