Grav API Plugin before 1.0.20 Authentication Bypass via Host Header (CVE-2026-86196) | HOL Guard CVE