Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token (CVE-2026-55088) | HOL Guard CVE