phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API (CVE-2026-85589) | HOL Guard CVE