pac4j-oidc before 6.5.6 Authentication Bypass via Access Token Substitution (CVE-2026-82462) | HOL Guard CVE