Authentication bypass via spoofed HTTP headers Orchestrator REST API (CVE-2026-63456) | HOL Guard CVE