Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange (CVE-2026-88006) | HOL Guard CVE