Graylog token revocation endpoint allows authenticated users to delete other users’ access tokens (CVE-2026-55867) | HOL Guard CVE