Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. (CVE-2026-54588) | HOL Guard CVE