# OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications

> OWASP published the 2026 update of the GenAI LLM Top 10, grounded in a curated dataset of 7,714 real-world AI security incidents (6,639 classified) and weighted 75% community expert voting / 25% incident data. The ranking introduces a hybrid evidence-based methodology, major positional shifts (Unbounded Consumption rose 4 positions, Improper Output Handling fell from 5th to 10th), and expands from 10 standalone risks to a cross-mapped framework spanning OWASP ASI/DSGAI, MITRE ATLAS/ATT&CK/CWE, NIST AI 600-1/RMF, and CSA AI Controls Matrix. Prompt Injection retains the top spot; Excessive Agency escalates as agentic systems see production incidents.

- **Published:** 2026-08-06T12:00:00Z
- **Last reviewed:** 2026-08-06T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1913
- **ID:** TL-2026-1913
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ASSESSING
- **Detections:** 9 · **IOCs:** 4 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-32711, CVE-2025-8217

## Description

The OWASP GenAI LLM Top 10 2026 (v1.0, published August 3, 2026) represents a fundamental methodological upgrade over the 2025 edition. For the first time, the ranking is not solely based on expert judgment but on a hybrid methodology weighting community practitioner voting at approximately 75% and real-world incident data analysis at 25%. The incident data was drawn from the genai_incidents v2.0.0 dataset (Emmanuel G. Junior Rodrigues, May 2026), which consolidates 7,714 publicly disclosed AI security incidents from sources including the OECD AI Incidents Monitor (~2,900 entries), AIAAIC (~1,500), and MIT FutureTech AI Risk Navigator (~400 new entries), normalized onto OWASP LLM, OWASP ASI, NIST AI RMF, and MITRE ATLAS taxonomies.

Led by Steve Wilson (Exabeam Chief AI Officer) and Rock Lambros (Zenity Director of AI Security), the 2026 edition features a top-10 list anchored by Prompt Injection (LLM01) at the top, followed by Sensitive Information Disclosure (LLM02), and Excessive Agency (LLM03) — the latter escalating significantly as production incidents cluster around agentic systems. Unbounded Consumption (LLM10 in 2025) rose four positions to LLM06, reflecting financial denial-of-service risks from extended-thinking models and shared compute environments. Misinformation (LLM07) climbed two positions after incident records showed extensive real-world harm from confident but incorrect model outputs triggering automated business workflows. Improper Output Handling dropped from 5th to 10th, not because the flaw is resolved, but because input-boundary prompt injections and cross-pipeline data disclosures now dominate incident records.

The 2026 edition documents 9 detailed attack scenarios for Prompt Injection alone, including direct injection, indirect injection via retrieved web content, unintentional injection, RAG repository poisoning (PoisonedRAG, USENIX Security 2025 — 5 injected documents achieving >95% attack success), payload splitting, multimodal steganographic injection (Clusmann et al., Nature Communications 2024), zero-click document-borne agentic exfiltration (CVE-2025-32711 EchoLeak, CVSS 9.3 Critical), agentic destructive command execution (AWS-2025-015, Amazon Q VS Code extension compromise reaching ~1 million installs), and trusted-backend indirect injection through MCP (Invariant Labs, General Analysis Supabase MCP, postmark-mcp package).

Each risk is characterized along anatomical axes (delivery surface, propagation behavior, encoding) and mapped to multiple industry frameworks. Hidden Context Exposure (LLM08) was broadened from the 2025 edition's System Prompt Leakage to cover all non-user-visible context including system prompts, policy logic, tool schemas, and guardrails. Vector and Embedding Weaknesses (LLM09) addresses RAG-specific broken access control, embedding inversion, cross-tenant leakage, and residual embeddings persisting after source data deletion (GDPR/CCPA compliance risk).

The project's guiding philosophy, articulated by the project leads, shifts focus from perfect prevention to blast-radius control: 'Stop trying to build a model that cannot be fooled. Build the system around it, so that when the model is fooled, and it will be, nothing important breaks.' This reframes AI security as an architectural and operational discipline rather than a model-alignment problem alone.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- AML.T0051 LLM Prompt Injection
- AML.T0051.000 Direct
- AML.T0051.001 Indirect
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- AML.T0054 LLM Jailbreak
- T1685 Disable or Modify Tools
- T1553 Subvert Trust Controls
- T1087 Account Discovery
- T1530 Data from Cloud Storage
- T1213 Data from Information Repositories
- T1048 Exfiltration Over Alternative Protocol
- AML.T0056 Extract LLM System Prompt
- T1485 Data Destruction
- T1565 Data Manipulation
- AML.T0034 Cost Harvesting

## Sources

- [OWASP GenAI LLM Top 10 2026](https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/)
- [Cyber Security News — OWASP GenAI LLM Top 10 2026](https://cybersecuritynews.com/owasp-genai-llm-top-10-2026/)
- [genai_incidents v2.0.0 — Incident Dataset](https://github.com/emmanuelgjr/genai_incidents/releases/tag/v2.0.0)
- [NIST AI 600-1 — Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf)
- [CVE-2025-32711 — EchoLeak (M365 Copilot Zero-Click Injection)](https://nvd.nist.gov/vuln/detail/cve-2025-32711)
- [AWS-2025-015 / CVE-2025-8217 — Amazon Q Extension Compromise](https://aws.amazon.com/security/security-bulletins/AWS-2025-015/)
- [PoisonedRAG — USENIX Security 2025](https://www.usenix.org/conference/usenixsecurity25/)
- [Clusmann et al. — Multimodal Steganographic Injection (Nature Communications 2024)](https://www.nature.com/articles/s41467-024-45678-9)
- [OWASP Top 10 for Agentic Applications (ASI)](https://genai.owasp.org/resource/owasp-agentic-top-10-2026/)
- [CSA AI Controls Matrix](https://cloudsecurityalliance.org/artifacts/ai-controls-matrix)
- [MITRE ATLAS Data Repository](https://github.com/mitre-atlas/atlas-data)
- [Invariant Labs — MCP Indirect Injection Research](https://invariantlabs.ai/blog/mcp-indirect-injection)
- [General Analysis — Supabase MCP Server Injection](https://generalanalysis.ai/blog/supabase-mcp-injection)
- [Aim Security — EchoLeak Research](https://www.aim.security/lp/aim-labs-echoleak-m365)
- [OWASP GenAI Security Project GitHub](https://github.com/GenAI-Security-Project/GenAI-LLM-Top10)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1913
