Combodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferences (CVE-2026-40877) | HOL Guard CVE