JSI Virtual Lightweight Collector: Default password is not required to be changed which allows unauthorized high-privileged access (CVE-2026-33784) | HOL Guard CVE