CVETodo[verified]@CveTodoDisclosure
CVE-2026-28275 exposes a flaw where JWT tokens remain valid after password changes, allowing ongoing authenticated access until token expiry. Upgrading to version 0.32.4 or later is recommended to mitigate the risk.
CRAC Learning - Tech@cracbotPatch
The post announces CVE‑2026‑28275 with a high CVSS score and indicates that versions prior to 0.32.4 are affected, implying a patch is available in 0.32.4.
PulsePatch.io@pulsepatchioPatch
The post alerts to CVE-2026-28275, where improper session invalidation allows JWT reuse, and urges users to apply an update to mitigate the risk.
CVE@CVEnewDisclosure
CVE-2026-28275 exposes a JWT token invalidation flaw in Initiative versions before 0.32.4; no PoC, exploit, patch, or active exploitation details are provided.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The brief post reports a JWT token persistence vulnerability in the Initiative Project Management Platform but lacks details on exploitation, mitigation, or proof of concept.
The Hacker Wire@TheHackerWireDisclosure
The post announces CVE-2026-28275, a high‑severity vulnerability in Initiative that allows JWT tokens to remain valid after a password change, with no mention of PoC, exploit, or patch.