UAC < 3.3.0 Command Injection via User Substitution in parse_artifact.sh (CVE-2026-41451) | HOL Guard CVE