Hard-coded Credentials in SmartIT Desktop Manager
SmartIT Desktop Manager contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to retrieve SSH service account credentials for the SmartIT Agent via application source code.
CVE search metadata
CVE search record: CVE-2026-85146. Severity: critical. CVSS: 9.8. KEV: no. Product: SmartIT Desktop Manager. Brief: Hard-coded Credentials in SmartIT Desktop Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-smartit-hardcoded-creds/
Lightstar SmartIT Desktop Manager is affected by a hard-coded credentials vulnerability (CVE-2026-85146). The vulnerability stems from the inclusion of SSH service account credentials directly within the application's source code. An unauthenticated remote attacker with access to the application binary or source code can extract these hard-coded secrets. Once obtained, the attacker can leverage these credentials to authenticate via SSH to any endpoint running the SmartIT Agent, potentially leading to full administrative control over the affected infrastructure. Given the critical nature of these credentials, this vulnerability poses a significant risk to organizations using the SmartIT Desktop Manager, as it provides a clear path for lateral movement and system compromise without requiring prior authentication.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized SSH access to internal systems managed by SmartIT Agents. This can result in complete system compromise, data exfiltration, and the ability to persist within the environment, impacting any organization utilizing the SmartIT Desktop Manager platform.
Recommendation
- Identify all instances of SmartIT Desktop Manager and SmartIT Agent within the environment.
- Contact Lightstar support to determine if a security update exists to remove hard-coded credentials.
- If no patch is available, isolate systems running the SmartIT Agent from untrusted networks and restrict SSH access to authorized management segments.
- Implement strict ingress filtering for SSH (TCP/22) to prevent unauthorized remote access using the exposed service account credentials.
Immediate actions
Inventory all hosts running SmartIT Desktop Manager or Agent.
Mitigations
Restrict inbound SSH access to SmartIT Agent endpoints to known administrative subnets.
CVE-2026-85146