Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects (CVE-2026-52821) | HOL Guard CVE