Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full database compromise and admin account takeover (CVE-2026-73847) | HOL Guard CVE