Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite (CVE-2026-87016) | HOL Guard CVE