Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context (CVE-2026-39900) | HOL Guard CVE