EverShop Missing Authorization on PATCH /api/customers/:id Allows Unauthenticated Account Takeover (CVE-2026-72843) | HOL Guard CVE