OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes (CVE-2026-19135) | HOL Guard CVE