Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user (CVE-2026-78336) | HOL Guard CVE