calibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification (CVE-2026-73249) | HOL Guard CVE