Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue.
Akka was affected by the same issue and has released the fix in version 1.6.1.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2025-16746 | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1. | 
|  Github GHSA | GHSA-9qvj-rpj8-v5c8 | Pekko Management may not properly apply authenticator when Basic Authentication enabled | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Wed, 02 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Akka Akka akka Management Apache Apache pekko Management | |
| CPEs | cpe:2.3:a:akka:akka_management:*:*:*:*:*:*:*:* cpe:2.3:a:apache:pekko_management:*:*:*:*:*:*:*:* | |
| Vendors & Products | Akka Akka akka Management Apache Apache pekko Management | 
Wed, 11 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1. | 
| Title | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management: management API basic authentication is not effective | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effective | 
Wed, 04 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References |  | 
Tue, 03 Jun 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. | |
| Title | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management: management API basic authentication is not effective | |
| Weaknesses | CWE-287 | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-06-11T17:44:23.190Z
Reserved: 2025-04-24T20:07:58.395Z
Link: CVE-2025-46548
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-06-03T18:03:45.963Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-06-03T15:15:59.110
Modified: 2025-07-02T14:19:10.130
Link: CVE-2025-46548
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.