SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85149

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The SmartIT Desktop Manager by Lightstar contains a vulnerability that exposes hard-coded SFTP service credentials, allowing unauthenticated remote attackers to access the source code and potentially browse the file system of affected hosts. This could lead to unauthorized data access or manipulation. Organizations using this software should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-85149
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%

Original NVD Description

SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.