Shopware: Unauthenticated data extraction possible through store-api.order endpoint (CVE-2026-31887) | HOL Guard CVE