File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope (CVE-2026-54094) | HOL Guard CVE