Apache Roller: Missing weblog authorization in XML-RPC Blogger/MetaWeblog handlers (CVE-2026-82377) | HOL Guard CVE