Privilege Escalation via System REST APIs in Multiple WSO2 Products Permits Admin Account Takeover (CVE-2026-1728) | HOL Guard CVE