Backstage: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass in `@backstage/plugin-auth-backend` (CVE-2026-73563) | HOL Guard CVE