InvenTree: Report/Label print endpoints ignore per-model permissions (CVE-2026-61748) | HOL Guard CVE