CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation (CVE-2026-54782) | HOL Guard CVE