ArcadeDB 26.4.2 before 26.8.1 Authorization Bypass via set_server_setting (CVE-2026-75845) | HOL Guard CVE