Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL (CVE-2026-48912) | HOL Guard CVE