Jenkins AppSpider Plugin does not perform a permission check in a method implementing form validation (CVE-2026-48923) | HOL Guard CVE