Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider (CVE-2026-68481) | HOL Guard CVE