Kimai: Pre-2FA KIMAI_SESSION cookie grants full authenticated REST API access, bypassing TOTP (CVE-2026-52827) | HOL Guard CVE