The ten risks of the OWASP Top 10 for Agentic Applications 2026 1: ASI01 Agent Goal Hijack, ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse, ASI04 Agentic Supply Chain Vulnerabilities, ASI05 Unexpected Code Execution (RCE), ASI06 Memory & Context Poisoning, ASI07 Insecure Inter-Agent Communication, ASI08 Cascading Failures, ASI09 Human-Agent Trust Exploitation and ASI10 Rogue Agents.
- Developed in
- ch. 23, Threats mapped to controls
ch. 08, OWASP GenAI Security Project - Chapters
- ch. 05, Patterns · ch. 08, Regulatory Map · ch. 23, AI Agents
- Source
- 1 numbered reference, listed below
Where it is used
2 chapters of the Body of Knowledge use the term. Each link opens the first section that does.
- 13 · Risk Management Risk, maturity and incidents 1 mention
- 23 · AI Agents What you can do this week 1 mention
Related terms
Sources
- [1] Top 10 for Agentic Applications 2026 (ASI01 Agent Goal Hijack; ASI02 Tool Misuse and Exploitation; ASI03 Identity and Privilege Abuse; ASI04 Agentic Supply Chain Vulnerabilities; ASI05 Unexpected Code Execution (RCE); ASI06 Memory & Context Poisoning; ASI07 Insecure Inter-Agent Communication; ASI08 Cascading Failures; ASI09 Human-Agent Trust Exploitation; ASI10 Rogue Agents; Least-Agency; per-tool least-privilege profiles; tool poisoning of a legitimate tool's interface under ASI02, a tool compromised at the source under ASI04). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .