Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation (CVE-2026-47229) | HOL Guard CVE