SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85147

HIGH · CVSS 7.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SmartIT Desktop Manager by Lightstar contains a vulnerability due to hard-coded credentials, allowing unauthenticated remote attackers to extract a specific password from the source code. This exploit can lead to unauthorized access to the AES encryption key used for secure communications, potentially compromising sensitive data. Organizations utilizing SmartIT Desktop Manager should prioritize remediation to mitigate the risk of data breaches and unauthorized access.

CVE
CVE-2026-85147
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.