GoCD is vulnerable to historical server configuration API authorization bypass (CVE-2026-52742) | HOL Guard CVE