Session Fixation in MISP CustomAuth Authentication Allows Session Hijacking (CVE-2026-85238) | HOL Guard CVE