Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation (CVE-2026-45738) | HOL Guard CVE