Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata (CVE-2026-54256) | HOL Guard CVE