Apache Tomcat: Servlet role references can bypass declarative role constraints (CVE-2026-66422) | HOL Guard CVE