Apache Roller: Cross-weblog resource tampering via unscoped authoring lookups (CVE-2026-82348) | HOL Guard CVE