Definition · AI security
OWASP LLM Top 10
The OWASP LLM Top 10, or OWASP Top 10 for Large Language Model Applications, is a ranked list of the ten most critical security risks in applications built on large language models, published by the OWASP GenAI Security Project. The current edition, released 4 August 2026, ranks entries by a practitioner vote weighted three-quarters and incident data weighted one-quarter.
Last reviewed
Key points
- The 2026 list, released 4 August 2026, runs from LLM01 Prompt Injection to LLM10 Improper Output Handling.
- For the first time, OWASP tested the practitioner vote against 7,714 real incidents, 6,639 of them detailed enough to classify. The vote carries three-quarters of the weight and the incident data one-quarter.
- OWASP calls Excessive Agency's rise from sixth to third the most consequential move from 2025. Improper Output Handling fell furthest, from fifth to tenth, and System Prompt Leakage became the broader Hidden Context Exposure.
- Entry IDs follow rank and change when entries move, so cite the year. LLM04 was Model Denial of Service in v1.1, Data and Model Poisoning in 2025, and Supply Chain in 2026.
- The list covers the model as a component of your application. When the model acts on its own, with tools and memory, OWASP advises reading this list together with its separate Top 10 for Agentic Applications, since many incidents sit on the boundary between them.
What is on the 2026 list
Entries are numbered by rank. The last column is each entry’s 2025 rank.
| 2026 | Entry | 2025 |
|---|---|---|
| LLM01 | Prompt Injection | 1 |
| LLM02 | Sensitive Information Disclosure | 2 |
| LLM03 | Excessive Agency | 6 |
| LLM04 | Supply Chain | 3 |
| LLM05 | Data and Model Poisoning | 4 |
| LLM06 | Unbounded Consumption | 10 |
| LLM07 | Misinformation | 9 |
| LLM08 | Hidden Context Exposure | 7, as System Prompt Leakage |
| LLM09 | Vector and Embedding Weaknesses | 8 |
| LLM10 | Improper Output Handling | 5 |
OWASP calls Excessive Agency’s climb the most consequential move: both the vote and the incident record point to agentic deployments as where the damage is happening. Unbounded Consumption climbed four places to Excessive Agency’s three, pushed up by the vote.
How the list is ranked
The 2026 ranking combines two signals. A community vote of practitioners carries three-quarters of the weight. Incident data carries the other quarter.
OWASP collected 7,714 real incidents from public vulnerability databases and one AI-harm database. Classifiers placed 6,639 of them, the ones with enough detail to sort. Earlier editions rested on practitioner judgment alone.
The two signals sometimes disagree. Ranked by incidents alone, prompt injection falls out of the top ten. OWASP reads this as a defense effect: because defenders work hard against injection, fewer successful attacks end up in public databases. It stays first. Misinformation runs the other way. The vote ranked it low and the incident record high, so it landed mid-list.
What else changed in 2026
Several entries widened as well as moved. OWASP chose to widen existing entries to cover newer risks instead of creating new, narrow ones. Prompt Injection now includes instructions hidden in an image or audio track. Supply Chain now covers a model file that a pipeline accepts into a trusted environment but that is not what it claims to be. Data and Model Poisoning now includes subverting a model through fine-tuning. Improper Output Handling now includes insecure code written by coding assistants.
Using the list
Cite the year with the ID. Entry IDs follow rank, so when an entry moves, its ID changes and the same ID can name different risks in different editions. LLM01 has stayed Prompt Injection, but others have not. LLM04 was Model Denial of Service in v1.1 (2023/24), Data and Model Poisoning in 2025, and Supply Chain in 2026. The 2026 files write IDs as LLM04:2026, and that form removes the ambiguity.
The model as component, not actor. OWASP draws the list’s boundary explicitly. It owns the risk when a model is a component inside an application. Once the model can call tools, keep memory between sessions and set consequences in motion, OWASP says the risk moves to the OWASP Top 10 for Agentic Applications. OWASP adds that many of the incidents it read sit on that boundary, and advises reading the two lists together when a model acts on its own.
Find the 2026 text. As of 27 September 2026 the list’s web page on
genai.owasp.org still shows the 2025 list, and the OWASP Foundation project
page sends readers there. The 2026 edition has its own publication page,
posted 3 August 2026. It also sits in the project’s GitHub repository. The
repository README gives the release date as 4 August 2026, and its
2026/final folder is the canonical source.
Map it to other frameworks. The 2026 edition maps its entries to other frameworks, among them NIST, CWE, the Agentic list and MITRE ATLAS. That helps a team that already tracks risks in one of them.
Questions and answers
What is the latest OWASP Top 10 for LLM applications?
The 2026 edition, released on 4 August 2026 according to the project's repository. In order it lists Prompt Injection, Sensitive Information Disclosure, Excessive Agency, Supply Chain, Data and Model Poisoning, Unbounded Consumption, Misinformation, Hidden Context Exposure, Vector and Embedding Weaknesses, and Improper Output Handling.
What changed between the 2025 and 2026 OWASP LLM Top 10?
Excessive Agency rose from sixth to third, Unbounded Consumption rose four places to sixth, and Improper Output Handling fell from fifth to tenth. System Prompt Leakage was renamed and widened into Hidden Context Exposure. The ranking also changed method, with incident data now carrying a quarter of the weight.
Is prompt injection still number one?
Yes. OWASP keeps it at LLM01 on the strength of the practitioner vote, although ranked by the public incident record alone it would fall out of the top ten. OWASP reads that gap as a defense effect, not a sign the risk is small.
What is the difference between the OWASP LLM Top 10 and the Agentic Top 10?
The LLM Top 10 covers the model as a component inside an application. OWASP's Top 10 for Agentic Applications covers the model as an actor, with tools it can call and memory it keeps between sessions. OWASP says to read the two together when a model acts on its own.
Sources
- OWASP Top 10 for LLM Applications 2026, release READMEOWASP GenAI Security Project, 4 Aug 2026
- OWASP Top 10 for LLM Applications 2026, LLM00 Preface (Letter from the Project Leads)OWASP GenAI Security Project, 4 Aug 2026
- OWASP Top 10 Risk & Mitigations for LLMs and Gen AI Apps 2025OWASP GenAI Security Project
- OWASP Top 10 for LLM Applications v1.1, archived entry filesOWASP
- OWASP Top 10 for Large Language Model Applications, OWASP Foundation project pageOWASP Foundation
- OWASP GenAI LLM Top 10 2026, resource pageOWASP GenAI Security Project