Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server (CVE-2026-18954) | HOL Guard CVE