CVE-2026-85149
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
- Published Sep 4, 2026
- CVSS 6.9 medium
- 0.4% chance of exploitation in the next 30 days (EPSS)