Instance template path traversal allows arbitrary host file write as root (CVE-2026-66897) | HOL Guard CVE