Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes (CVE-2026-87014) | HOL Guard CVE