Keycloak: Information disclosure of disabled user attributes via administrative endpoint (CVE-2026-3911) | HOL Guard CVE