Soft Machine: Unauthenticated workspace API exposes arbitrary file read & directory exfiltration to any peer on the Fly private network (CVE-2026-46711) | HOL Guard CVE