phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold (CVE-2026-57995) | HOL Guard CVE