Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement (CVE-2026-41235) | HOL Guard CVE