Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check (CVE-2026-70490) | HOL Guard CVE