A hard-coded JWT signing secret key may allow administrative functions to be abused using fraudulently generated Bearer tokens (CVE-2026-82827) | HOL Guard CVE