yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute (CVE-2026-59680) | HOL Guard CVE