Apache Roller: Reflected XSS in the optional LDAP comment authenticator (CVE-2026-91206) | HOL Guard CVE