PT-2026-22223 · Unknown · Initiative

G3Xar

·

Published

2026-02-26

·

Updated

2026-03-03

·

CVE-2026-28275

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Initiative versions prior to 0.32.4
Description Initiative, a self-hosted project management platform, does not invalidate previously issued JWT access tokens after a user changes their password. This allows older tokens to remain valid until their expiration, enabling continued authenticated access to protected API endpoints even after a password update. The vulnerable component is related to JWT (JSON Web Token) access token handling.
Recommendations Update to version 0.32.4 or later.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2026-28275
GHSA-HWW6-3FWW-XW3H

Affected Products

Initiative