Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission (CVE-2026-48508) | HOL Guard CVE