Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions (CVE-2026-3636) | HOL Guard CVE