Authentication bypass via spoofed HTTP headers Orchestrator REST API (CVE-2026-63455) | HOL Guard CVE