OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester (CVE-2026-100579) | HOL Guard CVE