XML External Entity (XXE) Injection via Schema Validation in Multiple WSO2 Products Allows File Reading and Denial of Service (CVE-2026-3415) | HOL Guard CVE