Label Studio through 1.23.0 Cross-Organization Annotation Access via Unscoped AnnotationAPI Queryset (CVE-2026-76073) | HOL Guard CVE