CVE-2026-28275Disclosure(morelitea / initiative)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch morelitea initiative systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access protected API endpoints. This behavior allows continued authenticated access even after the account password has been updated. Version 0.32.4 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-613

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • initiative

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
initiative

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-03: 102-2602-2702-2803-03
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-02-272
Disclosure1General1
2026-02-281
Patch1
2026-03-031
Patch1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Patch

    CVE-2026-28275 (CVSS:8.1, HIGH) is Analyzed. Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p..https://nvd.nist.gov/vuln/detail/CVE-2026-28275 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2026‑28275 with a high CVSS score and indicates that versions prior to 0.32.4 are affected, implying a patch is available in 0.32.4.

    0000034
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Improper session invalidation in `morelitea/initiative` (CVE-2026-28275) allows JWT reuse. Update to mitigate unauthorized access risk. #infosec #JWT #security https://www.pulsepatch.io/posts/cve-2026-28275-morelitea-initiative-session-invalidation

    Post summary

    The post alerts to CVE-2026-28275, where improper session invalidation allows JWT reuse, and urges users to apply an update to mitigate the risk.

    0000043
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28275 Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a use… https://www.cve.org/CVERecord?id=CVE-2026-28275

    Post summary

    CVE-2026-28275 exposes a JWT token invalidation flaw in Initiative versions before 0.32.4; no PoC, exploit, patch, or active exploitation details are provided.

    00000158
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-28275 JWT Token Persistence Vulnerability in Initiative Project Management Platform https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28275

    Post summary

    The brief post reports a JWT token persistence vulnerability in the Initiative Project Management Platform but lacks details on exploitation, mitigation, or proof of concept.

    0000038
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-28275** pertains to a security flaw in the self-hosted project management platform **Initiative**. Specifically, versions prior to **0.32.4** do not invalidate previously issued JWT (JSON Web Token) access tokens after a user changes their password. As a consequence, these older tokens remain valid until their natural expiration, allowing continued authenticated access to protected API endpoints even after a password update. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2026-28275

    Post summary

    CVE-2026-28275 exposes a flaw where JWT tokens remain valid after password changes, allowing ongoing authenticated access until token expiry. Upgrading to version 0.32.4 or later is recommended to mitigate the risk.

    0000038
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28275 - High Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password.... https://www.thehackerwire.com/vulnerability/CVE-2026-28275/ https://t.co/6xIVqirB5R

    Post summary

    The post announces CVE-2026-28275, a high‑severity vulnerability in Initiative that allows JWT tokens to remain valid after a password change, with no mention of PoC, exploit, or patch.

    0000038
    115 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmoreliteainitiative---

Explore more