SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85146

CRITICAL · CVSS 9.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The SmartIT Desktop Manager by Lightstar contains a critical vulnerability that exposes hard-coded SSH service account credentials, allowing unauthenticated remote attackers to access sensitive information directly from the application source code. This flaw poses a significant risk as it could lead to unauthorized system access and potential exploitation of the affected systems. Organizations using SmartIT Desktop Manager should prioritize immediate remediation to mitigate the risk of compromise.

CVE
CVE-2026-85146
Severity
CRITICAL
CVSS
9.8
EPSS
0.35%

Original NVD Description

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.