Broken disclosure embargo left admins facing a fresh root-level flaw with no CVE