KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR (CVE-2026-13612) | HOL Guard CVE