Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO (CVE-2026-45689) | HOL Guard CVE