PT-2026-22223 · Unknown · Initiative
G3Xar
·
Published
2026-02-26
·
Updated
2026-03-03
·
CVE-2026-28275
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Initiative versions prior to 0.32.4
Description
Initiative, a self-hosted project management platform, does not invalidate previously issued JWT access tokens after a user changes their password. This allows older tokens to remain valid until their expiration, enabling continued authenticated access to protected API endpoints even after a password update. The vulnerable component is related to JWT (JSON Web Token) access token handling.
Recommendations
Update to version 0.32.4 or later.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Initiative