Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass (CVE-2026-55207) | HOL Guard CVE