Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange (CVE-2026-88005) | HOL Guard CVE