pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers (CVE-2026-17350) | HOL Guard CVE