Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint (CVE-2026-54724) | HOL Guard CVE