ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch) (CVE-2026-28808) | HOL Guard CVE