Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client (CVE-2026-70482) | HOL Guard CVE