9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade (CVE-2026-56679) | HOL Guard CVE