Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentication or authorization checks. Any uploaded file can be accessed directly via its URL by unauthenticated users (e.g., in an incognito browser session), leading to potential disclosure of sensitive documents. The problem was patched in v0.32.2, and the patch was further improved on in 032.4.
References
| Link | Resource |
|---|---|
| https://github.com/Morelitea/initiative/releases/tag/v0.32.2 | Product Release Notes |
| https://github.com/Morelitea/initiative/security/advisories/GHSA-w34j-fx72-h2pq | Vendor Advisory |
Configurations
History
27 Feb 2026, 19:06
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Morelitea
Morelitea initiative |
|
| CPE | cpe:2.3:a:morelitea:initiative:*:*:*:*:*:*:*:* | |
| References | () https://github.com/Morelitea/initiative/releases/tag/v0.32.2 - Product, Release Notes | |
| References | () https://github.com/Morelitea/initiative/security/advisories/GHSA-w34j-fx72-h2pq - Vendor Advisory |
27 Feb 2026, 14:06
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
26 Feb 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-26 23:16
Updated : 2026-02-27 19:06
NVD link : CVE-2026-28276
Mitre link : CVE-2026-28276
CVE.ORG link : CVE-2026-28276
JSON object : View
Products Affected
morelitea
- initiative
