Kiwi TCMS's /init-db/ page renders and responds to requests after first use (CVE-2026-49292) | HOL Guard CVE