Apache Shiro: Auth bypass when accessing static files only on case-insensitive filesystems (CVE-2026-23903) | HOL Guard CVE