Flarum < 1.8.16 Session Persistence via Improper Access Token Revocation (CVE-2026-39924) | HOL Guard CVE