Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks (CVE-2026-32967) | HOL Guard CVE