OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection (CVE-2026-35210) | HOL Guard CVE