Apache CXF: OAuth2 Dynamic Client Registration Scope Self-Escalation (CVE-2026-61466) | HOL Guard CVE