Vaadin Vulnerable to Authentication Bypass When Accessing the /VAADIN Endpoint Without a Trailing Slash (CVE-2026-2742) | HOL Guard CVE