KiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOR (CVE-2026-19416) | HOL Guard CVE