Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search (CVE-2026-77051) | HOL Guard CVE