Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins (CVE-2026-16104) | HOL Guard CVE