Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users (CVE-2026-48507) | HOL Guard CVE