Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover (CVE-2026-52824) | HOL Guard CVE