Coolify: Account takeover via CSRF-able GET endpoint that resets password to attacker-known value (CVE-2026-34171) | HOL Guard CVE