Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh (CVE-2026-50199) | HOL Guard CVE