Automad has Broken Access Control: Unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint (CVE-2026-45332) | HOL Guard CVE