Zurück zur ÜbersichtBack to overview

OWASP LLM Top 10 2026: Die wichtigsten Änderungen gegenüber 2025OWASP LLM Top 10 2026: The Key Changes Compared to 2025

Die OWASP Top 10 für LLM-Anwendungen liegt in der Fassung 2026 vor. Zwei Einträge stehen unverändert an der Spitze, die Bewegung findet in der Mitte statt. Neu ist auch die Grundlage: Die Liste stützt sich erstmals nicht nur auf die Abstimmung von Fachleuten, sondern zusätzlich auf 7'714 ausgewertete Vorfälle, gewichtet mit drei Vierteln Abstimmung zu einem Viertel Daten.

Die Top 10 2026 im Überblick

Rangverschiebung der OWASP LLM Top 10 von 2025 auf 2026 Zwei Ranglisten nebeneinander, links 2025, rechts 2026. Linien verbinden jeden Eintrag mit seiner neuen Position. Excessive Agency steigt von Platz 6 auf 3, Unbounded Consumption von 10 auf 6, Misinformation von 9 auf 7. Improper Output Handling faellt von 5 auf 10. System Prompt Leakage heisst neu Hidden Context Exposure. 2025 2026 Prompt Injection 01 Sensitive Information Disclosure 02 Supply Chain 03 Data and Model Poisoning 04 Improper Output Handling 05 Excessive Agency 06 System Prompt Leakage 07 Vector and Embedding Weaknesses 08 Misinformation 09 Unbounded Consumption 10 01 Prompt Injection 02 Sensitive Information Disclosure 03 Excessive Agency 04 Supply Chain 05 Data and Model Poisoning 06 Unbounded Consumption 07 Misinformation 08 Hidden Context Exposure 09 Vector and Embedding Weaknesses 10 Improper Output Handling unverändert aufgestiegen abgestiegen umbenannt

Rangverschiebung von 2025 auf 2026. Die dickeren Linien markieren Sprünge über drei Plätze oder mehr.

2026Eintrag2025Bewegung
LLM01Prompt Injection01unverändert
LLM02Sensitive Information Disclosure02unverändert
LLM03Excessive Agency063 Plätze hoch
LLM04Supply Chain031 Platz runter
LLM05Data and Model Poisoning041 Platz runter
LLM06Unbounded Consumption104 Plätze hoch
LLM07Misinformation092 Plätze hoch
LLM08Hidden Context Exposure07umbenannt
LLM09Vector and Embedding Weaknesses081 Platz runter
LLM10Improper Output Handling055 Plätze runter

Was sich geändert hat

Excessive Agency steigt von 6 auf 3. OWASP nennt das die folgenreichste Verschiebung der Liste. Wer einem Modell Werkzeuge, Berechtigungen und Autonomie gibt, verwandelt eine Kompromittierung am Eingang in eine Handlung mit Aussenwirkung.

Unbounded Consumption steigt von 10 auf 6. Ressourcen- und Kostenerschöpfung wiegt in der Praxis schwerer als der alte Platz vermuten liess.

Improper Output Handling fällt von 5 auf 10 - der stärkste Abstieg. Keine Entwarnung, sondern eine Neugewichtung gegenüber Risiken, die schneller wachsen.

System Prompt Leakage heisst neu Hidden Context Exposure. Mehr als eine Umbenennung: Der Eintrag umfasst jetzt den gesamten verborgenen Kontext, also auch per RAG nachgeladene Richtlinien, Konfigurationen und die Schemata der Werkzeuge, die die Anwendung dem Modell zugänglich macht.

Vier bestehende Einträge wurden zudem erweitert, statt neue Kategorien zu schaffen: Prompt Injection deckt jetzt cross-modale Angriffe ab, also Anweisungen versteckt in Bild oder Ton. Supply Chain erfasst manipulierte Modell-Artefakte, Data and Model Poisoning die Unterwanderung über Fine-Tuning, und Improper Output Handling den unsicheren Code aus Coding-Assistenten.

Worauf Sie achten müssen

Agentenberechtigungen zuerst prüfen. Der Aufstieg von Excessive Agency ist die klarste Handlungsanweisung der neuen Liste. Zugangsdaten und zustandsverändernde Fähigkeiten gehören in den Anwendungscode, nicht in das Modell. Berechtigungen werden pro Vorgang vergeben, nicht als bequemer Sammelzugriff.

Den Systemprompt nicht als Geheimnis behandeln. Wenn eine Richtlinie nur deshalb hält, weil niemand den verborgenen Kontext kennt, ist sie keine Kontrolle. Er darf keine Zugangsdaten enthalten und nie allein als Sicherheitsgrenze für Autorisierung dienen.

Kostenerschöpfung in die Risikobetrachtung aufnehmen. Unbegrenzter Verbrauch ist selten Teil klassischer Sicherheitsbewertungen und steht jetzt auf Platz 6.

Die Grenze zur Agentic Top 10 kennen. Diese Liste beansprucht nur den Fall, in dem das Modell ein Bauteil Ihrer Anwendung ist. Sobald es zum Akteur wird, mit Werkzeugen und Gedächtnis über Sitzungen hinweg, wandert das Risiko in die OWASP Agentic Top 10. Eine Risikoanalyse, die nur die LLM-Liste abarbeitet, hat bei agentischen Systemen eine Lücke.

Gegen adaptive Angreifer testen. Das Dokument verweist auf Untersuchungen, in denen statische Angriffe nahe null Erfolg hatten, während adaptive Angriffe gegen die meisten von zwölf aktuellen Abwehrmechanismen über 90 Prozent erreichten.

Hinweis zur Quelle: Dieser Beitrag stützt sich auf das Dokument "OWASP Top 10 for LLM Applications 2026" (Version 1.0) des OWASP GenAI Security Project, veröffentlicht unter CC BY-SA 4.0.

The OWASP Top 10 for LLM Applications is now available in its 2026 edition. Two entries hold the top unchanged, the movement happens in the middle. The basis is new as well: for the first time the list rests not only on the vote of practitioners but additionally on 7,714 analysed incidents, weighted three quarters vote to one quarter data.

The 2026 Top 10 at a Glance

Rank migration of the OWASP LLM Top 10 from 2025 to 2026 Two rankings side by side, 2025 on the left, 2026 on the right. Lines connect each entry to its new position. Excessive Agency climbs from 6 to 3, Unbounded Consumption from 10 to 6, Misinformation from 9 to 7. Improper Output Handling falls from 5 to 10. System Prompt Leakage is now Hidden Context Exposure. 2025 2026 Prompt Injection 01 Sensitive Information Disclosure 02 Supply Chain 03 Data and Model Poisoning 04 Improper Output Handling 05 Excessive Agency 06 System Prompt Leakage 07 Vector and Embedding Weaknesses 08 Misinformation 09 Unbounded Consumption 10 01 Prompt Injection 02 Sensitive Information Disclosure 03 Excessive Agency 04 Supply Chain 05 Data and Model Poisoning 06 Unbounded Consumption 07 Misinformation 08 Hidden Context Exposure 09 Vector and Embedding Weaknesses 10 Improper Output Handling unchanged escalated deprioritized renamed

Rank migration from 2025 to 2026. Thicker lines mark moves of three places or more.

2026Entry2025Movement
LLM01Prompt Injection01unchanged
LLM02Sensitive Information Disclosure02unchanged
LLM03Excessive Agency06up 3
LLM04Supply Chain03down 1
LLM05Data and Model Poisoning04down 1
LLM06Unbounded Consumption10up 4
LLM07Misinformation09up 2
LLM08Hidden Context Exposure07renamed
LLM09Vector and Embedding Weaknesses08down 1
LLM10Improper Output Handling05down 5

What Has Changed

Excessive Agency climbs from 6 to 3. OWASP calls this the most consequential move on the list. Giving a model tools, permissions and autonomy turns a compromise at the input into an action with external effect.

Unbounded Consumption climbs from 10 to 6. Resource and cost exhaustion weighs more heavily in practice than its old rank suggested.

Improper Output Handling falls from 5 to 10 - the steepest drop. Not an all-clear but a reweighting against risks that are growing faster.

System Prompt Leakage is now Hidden Context Exposure. More than a rename: the entry now covers the entire hidden context, including policy text retrieved via RAG, configurations and the schemas of the tools the application exposes to the model.

Four existing entries were also broadened rather than replaced by new categories: Prompt Injection now covers cross-modal attacks, meaning instructions hidden in an image or audio track. Supply Chain accounts for manipulated model artefacts, Data and Model Poisoning for subversion through fine-tuning, and Improper Output Handling for the insecure code produced by coding assistants.

What to Watch For

Review your agent permissions first. The rise of Excessive Agency is the clearest instruction the new list gives. Credentials and state-changing capability belong in application code, not in the model. Permissions are granted per operation, not as a convenient blanket grant.

Do not treat your system prompt as a secret. If a policy only holds because nobody knows the hidden context, it is not a control. It must not contain credentials and must never serve on its own as a security boundary for authorisation.

Include cost exhaustion in your risk assessment. Unbounded consumption is rarely part of classic security reviews and now sits at number 6.

Know the boundary to the Agentic Top 10. This list claims only the case where the model is a component of your application. The moment it becomes an actor, with tools and memory carried between sessions, the risk moves to the OWASP Agentic Top 10. A risk analysis that works through the LLM list alone has a gap when it comes to agentic systems.

Test against adaptive attackers. The document cites research in which static attacks had near zero success while adaptive attacks exceeded 90 percent against most of twelve recent defences.

Note on the source: This article draws on the document "OWASP Top 10 for LLM Applications 2026" (version 1.0) by the OWASP GenAI Security Project, published under CC BY-SA 4.0.