Magistrala (formerly Mainflux) IoT Platform SQL Injection via format Query Parameter (CVE-2026-71276) | HOL Guard CVE