Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers (CVE-2026-84801) | HOL Guard CVE