Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes (CVE-2026-49992) | HOL Guard CVE