samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions (CVE-2026-46490) | HOL Guard CVE