Combodo iTop: Object can be locked by a user without write permissions (CVE-2026-33047) | HOL Guard CVE