Session id is not renewed on authentication in ash_authentication, allowing session fixation (CVE-2026-86688) | HOL Guard CVE