Apache Ranger: Download APIs expose plugin data without authentication (CVE-2026-55814) | HOL Guard CVE