InvoicePlane: Primary Administrator Privilege Downgrade via `Users::form()` (Missing Object-Level Authorization) (CVE-2026-100392) | HOL Guard CVE