CVE-2026-40968 — When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the s — CVE Database · The Intelligence Room