Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant (CVE-2026-1486) | HOL Guard CVE