Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation (CVE-2026-96448) | HOL Guard CVE