OpenClaw < 2026.4.22 - Owner Context Spoofing via Bearer Token Header (CVE-2026-44118) | HOL Guard CVE