OpenClaw < 2026.5.4 - Unauthorized Device-Pairing Bootstrap Code Issuance via Chat Command (CVE-2026-32905) | HOL Guard CVE