Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin (CVE-2026-57111) | HOL Guard CVE