NoSQL injection via array replacement bypassing update shape validation in driver write path (CVE-2026-81528) | HOL Guard CVE