InvenTree: Plugin-settings GET endpoints are readable without authentication (CVE-2026-61746) | HOL Guard CVE