Keycloak: Session fixation in OIDC login flow that can lead to account takeover (CVE-2026-7507) | HOL Guard CVE