Grafana: Users can generate Service Account tokens after permissions removal (CVE-2026-33381) | HOL Guard CVE