Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates (CVE-2026-47838) | HOL Guard CVE