OWASP Top 10 for LLM Applications 2026 — roadmap coverage
Absorption crosswalk for the OWASP Top 10 for LLM Applications, 2026 v1.0
(OWASP GenAI Security Project). Each 2026 risk
is mapped to the week(s) that teach it, so you can see the book covers the standard —
and where the 2026 changes landed. Read alongside AI-300 · OSAI (the exam crosswalk).
What changed in 2026 (vs 2025)
- ⬆️ Excessive Agency promoted to #3 (was LLM06) — agentic risk is now front-of-list.
- 🔀 Unbounded Consumption → LLM06, Misinformation → LLM07, Vector & Embedding → LLM09, Improper Output Handling → LLM10 (all re-ranked).
- 🆕 LLM08 Hidden Context Exposure — replaces/broadens the old "System Prompt Leakage": extraction/inference/reconstruction of hidden system instructions, tool/function schemas, policy logic, and trust boundaries. Core rule: assume hidden context is discoverable; never rely on the system prompt as a security boundary.
- 🧭 Heavy agentic framing throughout, with hand-offs to the sibling OWASP tops: ASI (Agentic Apps) and DSGAI (GenAI Data Security), plus MITRE ATLAS/ATT&CK mappings.
- 🔑 New load-bearing concepts: the lethal trifecta (private data + untrusted input + external comms), the Rule of Two, adaptive-attack testing (static ≈0% vs adaptive >90%), reasoning-token / thinking-token exhaustion, retrieval jamming, Whisper Leak side-channels, slopsquatting, and complete mediation / deterministic policy engines.
Crosswalk
| # | 2026 risk | Roadmap week(s) | Coverage |
|---|---|---|---|
| LLM01 | Prompt Injection | W9 Prompt Hacking · W10 Semantic Exploitation · W14 Red Teaming · W18 Bidirectional Defense | ✅ strong |
| LLM02 | Sensitive Information Disclosure | W11 Adversarial ML (inversion/side-channels) · W24 Compliance · W19 Infra | ✅ added: Whisper Leak / inference side-channels, the 4-phase disclosure model |
| LLM03 | Excessive Agency | W5 Agentic Core · W21 Agentic Safety/Control | ✅ added: complete mediation / graduated enforcement (audit→warn→block→escalate) |
| LLM04 | Supply Chain | W16 Supply Chain & Lifecycle | ✅ added: slopsquatting, PEFT/LoRA-adapter provenance, model-artifact conversion |
| LLM05 | Data & Model Poisoning | W11 · W12 RAG Poisoning · W16 | ✅ strong |
| LLM06 | Unbounded Consumption | W21 Agentic Safety · W19/W20 Infra/MLSecOps | ✅ added: Denial-of-Wallet, reasoning-token exhaustion, agentic circuit breakers, hard spend caps |
| LLM07 | Misinformation | W17 Guardrails · W25 IR & Forensics · W7 MCP | ✅ added: Claim-Check-Act, cross-agent misinformation propagation, groundedness signals |
| LLM08 | Hidden Context Exposure 🆕 | W8 Threat Modeling · W15 MCP/Protocol Hijacking · W9 | ✅ added (W8) — hidden context discoverable, tool-schema exposure, no-secrets-in-context, deterministic authz outside the model |
| LLM09 | Vector & Embedding Weaknesses | W4 RAG · W11 Adversarial ML · W12 RAG Poisoning | ✅ added: retrieval jamming, cross-tenant similarity leakage, membership-inference oracle |
| LLM10 | Improper Output Handling | W18 Bidirectional Defense · W13 Agentic Pentesting | ✅ strong (SQLi/XSS/unsafe-exec from model output) |
Absorption status — ✅ COMPLETE (2026-08-10)
The full 2026 Top 10 is now absorbed at exam depth. The audit's one true gap (LLM08 Hidden Context Exposure) and every thin 2026 concept were filled non-destructively across 6 weeks (W8, W11, W12, W16, W17, W21) — all self-assessed full, ~40 subtopics added with ~30 cited sources — and released in the roadmap editions. Specifically now covered: retrieval jamming, Whisper-Leak / inference side-channels, Denial-of-Wallet & reasoning-token exhaustion, agentic circuit breakers, slopsquatting & LoRA-adapter provenance, complete mediation, and Claim-Check-Act.
🔗 The doc also ships framework mappings (Appendix A): ASI (Agentic), DSGAI (Data Security), MITRE ATLAS v2026.06, ATT&CK v19.1, CWE 4.20, NIST AI 600-1 / AI RMF, CSA AICM, OWASP AIVSS — useful cross-references for W22 Risk Frameworks and W23 MITRE ATLAS.