Logto: Account API can disclose stored third-party provider tokens without the identities scope (CVE-2026-63203) | HOL Guard CVE