Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log (CVE-2026-77425) | HOL Guard CVE