pgAdmin 4: Authentication bypass via a client-controlled identity header in Webserver authentication mode (CVE-2026-86863) | HOL Guard CVE