CVE-2026-28275 Details
Description
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access protected API endpoints. This behavior allows continued authenticated access even after the account password has been updated. Version 0.32.4 fixes the issue.
A vulnerability exists in the Morelitea Initiative project management platform in versions prior to 0.32.4, where the application fails to invalidate JSON Web Tokens (JWT) after a user changes their password. This oversight allows older tokens to remain valid until they expire, enabling continued access to protected API endpoints. The issue arises because there is no mechanism to revoke or invalidate tokens after a password change, leaving accounts vulnerable to unauthorized access.
Users can update to Morelitea Initiative version 0.32.4 or later, where this vulnerability is addressed. Instructions for downloading the latest version are available on the Morelitea Initiative GitHub release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Morelitea/initiative/releases/tag/v0.32.4 | [email protected] | ProductRelease Notes |
| https://github.com/Morelitea/initiative/security/advisories/GHSA-hww6-3fww-xw3h | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| morelitea initiative | < 0.32.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Feb 26, 2026 | New CVE Received | [email protected] |