Bookit < 2.6.0.5 - Bookit Staff+ Arbitrary Appointment Deletion via Missing Authorization (CVE-2026-89007) | HOL Guard CVE