CVE-2026-85146
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
- Published Sep 4, 2026
- CVSS 9.3 critical
- 0.6% chance of exploitation in the next 30 days (EPSS)