Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor` (CVE-2026-49870) | HOL Guard CVE