Cyber & AI intelligence
Wasteland.
Briefs indexed2410
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-85148 2026-09-04

CVE-2026-85148: Hard-Coded Credentials in Lightstar SmartIT Desktop Manager Allow Unauthenticated Remote Access

"A fixed, hard-coded password in Lightstar's SmartIT Desktop Manager lets unauthenticated remote attackers reach and control managed user hosts, earning a CVSS 3.1 base score of 9.8 (Critical)."

A fixed, hard-coded password in Lightstar's SmartIT Desktop Manager lets unauthenticated remote attackers reach and control managed user hosts, earning a CVSS 3.1 base score of 9.8 (Critical).

What Is It

CVE-2026-85148 is a Use of Hard-coded Credentials flaw (CWE-798) in SmartIT Desktop Manager, developed by Lightstar. According to the advisory from TWCERT/CC, the product ships with a fixed password that unauthenticated remote attackers can use to remotely access user hosts.

The CVE was published on 2026-09-04 and is currently in "Received" status at NVD, meaning it has not yet completed NVD analysis. Two severity ratings are supplied by the reporting CNA:

Why It Matters

Both vectors describe the worst-case exploitation profile: network-reachable, low attack complexity, no privileges, and no user interaction, with high impact to confidentiality, integrity, and availability. Hard-coded credentials typically cannot be rotated away through normal administrative controls, and if the password is identical across deployments, as the advisory's description of a fixed shipped password suggests, anyone who learns it would gain access to any exposed installation that has not been remediated by the vendor. The supplied data does not specify whether the credential is per-install or shared, so defenders should confirm this with the vendor.

Because SmartIT Desktop Manager is endpoint management software, the compromise target is the managed user hosts themselves, not just the management console.

There is no CISA KEV entry for this CVE in the supplied data, so active exploitation is not confirmed at this time.

What's Vulnerable

No CPE entries have been assigned to this record yet.

Patch Status

The supplied NVD record contains no patch, fixed-version, mitigation, or vendor remediation information, and no KEV-mandated required action or due date. Defenders should consult the TWCERT/CC advisories below for vendor guidance and treat internet-exposed instances as high priority pending confirmation of a fixed release.

Sources