Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts (CVE-2026-45675) | HOL Guard CVE