FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope (CVE-2026-54239) | HOL Guard CVE