Bookly < 28.2 - Unauthenticated AI Assistant Conversation Disclosure and Message Injection via IDOR (CVE-2026-91847) | HOL Guard CVE