CVE-2026-23920 — Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected ne — CVE Database · The Intelligence Room