New API: Admin can reset passkeys for same-level or higher-privileged users (CVE-2026-64866) | HOL Guard CVE