Leantime JSON-RPC API contains a missing authorization vulnerability (CVE-2026-76647) | HOL Guard CVE