nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation (CVE-2026-47724) | HOL Guard CVE