Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints (CVE-2026-88959) | HOL Guard CVE