Source directoryOWASP Foundation2026
OWASP Top 10 for Agentic Applications for 2026
“OWASP Top 10 for Agentic Applications for 2026”. Publisher: OWASP Foundation. Version used: 2026. The Versatile AI Risk Assessment threat catalogue backs 6 of its 52 threats with this document, at 6 verified locations.
Document details
- Publisher
- OWASP Foundation
- Version used
- 2026
- Year
- not stated
- Licence
- not stated
- Framework
- OWASP LLM Top 10
Open the original document at the publisher External link; the publisher’s version always takes precedence.
References in the catalogue (6)
Every row states the clause, its title, the exact location in the document and the threats that refer to it.
| Clause | Title and location | Referencing threats |
|---|---|---|
ASI01:2026 |
Agent Goal Hijack ASI01 Agent Goal Hijack, pp. 9–11 of the official PDF | Agentic AI / Autonomous AgentsMCP Hijacking (Model Context Protocol) |
ASI02:2026 |
Tool Misuse and Exploitation ASI02 Tool Misuse and Exploitation, pp. 12–14 of the official PDF | Insecure Tool DesignAgentic AI / Autonomous AgentsMCP Hijacking (Model Context Protocol) |
ASI04:2026 |
Agentic Supply Chain Vulnerabilities ASI04 Agentic Supply Chain Vulnerabilities, pp. 18–20 of the official PDF | MCP Hijacking (Model Context Protocol) |
ASI06:2026 |
Memory & Context Poisoning ASI06 Memory & Context Poisoning, pp. 24–26 of the official PDF | RAG-Specific Attacks (Document Poisoning)Agent Memory Poisoning (Persistent Context) |
ASI07:2026 |
Insecure Inter-Agent Communication ASI07 Insecure Inter-Agent Communication, pp. 27–29 of the official PDF | Insecure Inter-Agent Communication (A2A/MCP) |
ASI08:2026 |
Cascading Failures ASI08 Cascading Failures, pp. 30–32 of the official PDF | Agentic AI / Autonomous Agents |
This page does not reproduce the text of the standards. It states the identifier, title and location of the clause; the wording itself is in the original document. The mappings are taxonomic and not evidence of compliance.
Threats referencing this document (6)
Grouped by topic. Every entry leads to the full threat page.
Agentic and Autonomous AI
Application and Integration Security
More documents from the same publisher
All documents by OWASP Foundation cited in the catalogue.
From the reference to the assessment
The full catalogue states the mitigations, the possible impact and every verified location for each threat. The live demo runs locally in your browser, with no sign-up.
Cite this page
For reports, policies or internal documents; the link leads directly to this source page.
“OWASP Top 10 for Agentic Applications for 2026” (OWASP Foundation). References in the AI threat catalogue, Versatile AI Risk Assessment, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/sources/owasp-top-10-agentic-applications-2026/