@actual-app/sync-server: Disabled OpenID users keep access through existing session tokens (CVE-2026-49229) | HOL Guard CVE