LDAP injection in MISP ApacheAuthenticate when using a user-controlled Apache environment variable (CVE-2026-39962) | HOL Guard CVE