Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes (CVE-2026-52823) | HOL Guard CVE