Eda-server: websocket missing authorization allows credential theft via activation_id spoofing (CVE-2026-11807) | HOL Guard CVE