Pathling: Explicit oauthMetadataUrl in bulk-submit allows OAuth client credential exfiltration (CVE-2026-47660) | HOL Guard CVE