Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate (CVE-2026-84797) | HOL Guard CVE