django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff (CVE-2026-61663) | HOL Guard CVE