CVE-2026-19349: OAuth2 State Parameter Mishandling Enables SSO Authentication Bypass — Casky — Casky