Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication (CVE-2026-33557) | HOL Guard CVE