CakePHP Authentication: Open redirect weakness via backslash bypass (CVE-2026-55590) | HOL Guard CVE