Concrete CMS has a session-hardening bypass and allows password change without reauthorization (CVE-2026-8327) | HOL Guard CVE