Cacti: Session Fixation via missing session_regenerate_id() after login (CVE-2026-40082) | HOL Guard CVE