OpenWA: A read-only API key can receive a session pairing QR over the WebSocket event stream (CVE-2026-91160) | HOL Guard CVE