[mcp-atlassian] Authentication bypass in HTTP transport: AtlassianOpaqueTokenVerifier accepts any non-empty token (CVE-2026-77244) | HOL Guard CVE