Apache Answer: Unauthenticated OAuth Email-Binding Account Takeover via Existing User Confirmation Flow (CVE-2026-48911) | HOL Guard CVE