Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php (CVE-2026-39955) | HOL Guard CVE