Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator (CVE-2026-50627) | HOL Guard CVE