Fleet applies namespace labels and annotations without the bundle's service account privileges (CVE-2026-93540) | HOL Guard CVE