Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation (CVE-2026-73292) | HOL Guard CVE