Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster (CVE-2026-17107) | HOL Guard CVE