Opencast: Session fixation in login enables account takeover via crafted link (CVE-2026-77614) | HOL Guard CVE