Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions (CVE-2026-54593) | HOL Guard CVE