Horilla attendance approval endpoint is vulnerable to cross-site request forgery (CVE-2026-86066) | HOL Guard CVE