FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions (CVE-2026-27604) | HOL Guard CVE