{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alightstarsmartit_desktop_manager/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lightstar:smartit_desktop_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-85146"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SmartIT Desktop Manager"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","credential-exposure","remote-access"],"_cs_type":"advisory","_cs_vendors":["Lightstar"],"content_html":"\u003cp\u003eLightstar SmartIT Desktop Manager is affected by a hard-coded credentials vulnerability (CVE-2026-85146). The vulnerability stems from the inclusion of SSH service account credentials directly within the application's source code. An unauthenticated remote attacker with access to the application binary or source code can extract these hard-coded secrets. Once obtained, the attacker can leverage these credentials to authenticate via SSH to any endpoint running the SmartIT Agent, potentially leading to full administrative control over the affected infrastructure. Given the critical nature of these credentials, this vulnerability poses a significant risk to organizations using the SmartIT Desktop Manager, as it provides a clear path for lateral movement and system compromise without requiring prior authentication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized SSH access to internal systems managed by SmartIT Agents. This can result in complete system compromise, data exfiltration, and the ability to persist within the environment, impacting any organization utilizing the SmartIT Desktop Manager platform.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of SmartIT Desktop Manager and SmartIT Agent within the environment.\u003c/li\u003e\n\u003cli\u003eContact Lightstar support to determine if a security update exists to remove hard-coded credentials.\u003c/li\u003e\n\u003cli\u003eIf no patch is available, isolate systems running the SmartIT Agent from untrusted networks and restrict SSH access to authorized management segments.\u003c/li\u003e\n\u003cli\u003eImplement strict ingress filtering for SSH (TCP/22) to prevent unauthorized remote access using the exposed service account credentials.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T03:24:07Z","date_published":"2026-09-04T03:24:07Z","id":"https://feed.craftedsignal.io/briefs/2026-09-smartit-hardcoded-creds/","summary":"SmartIT Desktop Manager contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to retrieve SSH service account credentials for the SmartIT Agent via application source code.","title":"Hard-coded Credentials in SmartIT Desktop Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-smartit-hardcoded-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:lightstar:smartit_desktop_manager:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}