Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup (CVE-2026-44177) | HOL Guard CVE