mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind (CVE-2026-49257) | HOL Guard CVE