OpenC3 COSMOS: Hijacked session token can be used to reset password for persistence (CVE-2026-42084) | HOL Guard CVE