Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation (CVE-2026-91012) | HOL Guard CVE