Apache Syncope: Cross-Realm authorization bypass in delegated administration (CVE-2026-73236) | HOL Guard CVE