Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header (CVE-2026-4525) | HOL Guard CVE