Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` (CVE-2026-58269) | HOL Guard CVE