GRC & Compliance4. August 20264 August 20263 Min. Lesezeit3 min read
OWASP LLM Top 10 2026: Die wichtigsten Änderungen gegenüber 2025OWASP LLM Top 10 2026: The Key Changes Compared to 2025
Die OWASP Top 10 für LLM-Anwendungen liegt in der Fassung 2026 vor. Zwei Einträge stehen unverändert an der Spitze, die Bewegung findet in der Mitte statt. Neu ist auch die Grundlage: Die Liste stützt sich erstmals nicht nur auf die Abstimmung von Fachleuten, sondern zusätzlich auf 7'714 ausgewertete Vorfälle, gewichtet mit drei Vierteln Abstimmung zu einem Viertel Daten.
Die Top 10 2026 im Überblick
Rangverschiebung von 2025 auf 2026. Die dickeren Linien markieren Sprünge über drei Plätze oder mehr.
2026
Eintrag
2025
Bewegung
LLM01
Prompt Injection
01
unverändert
LLM02
Sensitive Information Disclosure
02
unverändert
LLM03
Excessive Agency
06
3 Plätze hoch
LLM04
Supply Chain
03
1 Platz runter
LLM05
Data and Model Poisoning
04
1 Platz runter
LLM06
Unbounded Consumption
10
4 Plätze hoch
LLM07
Misinformation
09
2 Plätze hoch
LLM08
Hidden Context Exposure
07
umbenannt
LLM09
Vector and Embedding Weaknesses
08
1 Platz runter
LLM10
Improper Output Handling
05
5 Plätze runter
Was sich geändert hat
Excessive Agency steigt von 6 auf 3. OWASP nennt das die folgenreichste Verschiebung der Liste. Wer einem Modell Werkzeuge, Berechtigungen und Autonomie gibt, verwandelt eine Kompromittierung am Eingang in eine Handlung mit Aussenwirkung.
Unbounded Consumption steigt von 10 auf 6. Ressourcen- und Kostenerschöpfung wiegt in der Praxis schwerer als der alte Platz vermuten liess.
Improper Output Handling fällt von 5 auf 10 - der stärkste Abstieg. Keine Entwarnung, sondern eine Neugewichtung gegenüber Risiken, die schneller wachsen.
System Prompt Leakage heisst neu Hidden Context Exposure. Mehr als eine Umbenennung: Der Eintrag umfasst jetzt den gesamten verborgenen Kontext, also auch per RAG nachgeladene Richtlinien, Konfigurationen und die Schemata der Werkzeuge, die die Anwendung dem Modell zugänglich macht.
Vier bestehende Einträge wurden zudem erweitert, statt neue Kategorien zu schaffen: Prompt Injection deckt jetzt cross-modale Angriffe ab, also Anweisungen versteckt in Bild oder Ton. Supply Chain erfasst manipulierte Modell-Artefakte, Data and Model Poisoning die Unterwanderung über Fine-Tuning, und Improper Output Handling den unsicheren Code aus Coding-Assistenten.
Worauf Sie achten müssen
Agentenberechtigungen zuerst prüfen. Der Aufstieg von Excessive Agency ist die klarste Handlungsanweisung der neuen Liste. Zugangsdaten und zustandsverändernde Fähigkeiten gehören in den Anwendungscode, nicht in das Modell. Berechtigungen werden pro Vorgang vergeben, nicht als bequemer Sammelzugriff.
Den Systemprompt nicht als Geheimnis behandeln. Wenn eine Richtlinie nur deshalb hält, weil niemand den verborgenen Kontext kennt, ist sie keine Kontrolle. Er darf keine Zugangsdaten enthalten und nie allein als Sicherheitsgrenze für Autorisierung dienen.
Kostenerschöpfung in die Risikobetrachtung aufnehmen. Unbegrenzter Verbrauch ist selten Teil klassischer Sicherheitsbewertungen und steht jetzt auf Platz 6.
Die Grenze zur Agentic Top 10 kennen. Diese Liste beansprucht nur den Fall, in dem das Modell ein Bauteil Ihrer Anwendung ist. Sobald es zum Akteur wird, mit Werkzeugen und Gedächtnis über Sitzungen hinweg, wandert das Risiko in die OWASP Agentic Top 10. Eine Risikoanalyse, die nur die LLM-Liste abarbeitet, hat bei agentischen Systemen eine Lücke.
Gegen adaptive Angreifer testen. Das Dokument verweist auf Untersuchungen, in denen statische Angriffe nahe null Erfolg hatten, während adaptive Angriffe gegen die meisten von zwölf aktuellen Abwehrmechanismen über 90 Prozent erreichten.
Hinweis zur Quelle: Dieser Beitrag stützt sich auf das Dokument "OWASP Top 10 for LLM Applications 2026" (Version 1.0) des OWASP GenAI Security Project, veröffentlicht unter CC BY-SA 4.0.
The OWASP Top 10 for LLM Applications is now available in its 2026 edition. Two entries hold the top unchanged, the movement happens in the middle. The basis is new as well: for the first time the list rests not only on the vote of practitioners but additionally on 7,714 analysed incidents, weighted three quarters vote to one quarter data.
The 2026 Top 10 at a Glance
Rank migration from 2025 to 2026. Thicker lines mark moves of three places or more.
2026
Entry
2025
Movement
LLM01
Prompt Injection
01
unchanged
LLM02
Sensitive Information Disclosure
02
unchanged
LLM03
Excessive Agency
06
up 3
LLM04
Supply Chain
03
down 1
LLM05
Data and Model Poisoning
04
down 1
LLM06
Unbounded Consumption
10
up 4
LLM07
Misinformation
09
up 2
LLM08
Hidden Context Exposure
07
renamed
LLM09
Vector and Embedding Weaknesses
08
down 1
LLM10
Improper Output Handling
05
down 5
What Has Changed
Excessive Agency climbs from 6 to 3. OWASP calls this the most consequential move on the list. Giving a model tools, permissions and autonomy turns a compromise at the input into an action with external effect.
Unbounded Consumption climbs from 10 to 6. Resource and cost exhaustion weighs more heavily in practice than its old rank suggested.
Improper Output Handling falls from 5 to 10 - the steepest drop. Not an all-clear but a reweighting against risks that are growing faster.
System Prompt Leakage is now Hidden Context Exposure. More than a rename: the entry now covers the entire hidden context, including policy text retrieved via RAG, configurations and the schemas of the tools the application exposes to the model.
Four existing entries were also broadened rather than replaced by new categories: Prompt Injection now covers cross-modal attacks, meaning instructions hidden in an image or audio track. Supply Chain accounts for manipulated model artefacts, Data and Model Poisoning for subversion through fine-tuning, and Improper Output Handling for the insecure code produced by coding assistants.
What to Watch For
Review your agent permissions first. The rise of Excessive Agency is the clearest instruction the new list gives. Credentials and state-changing capability belong in application code, not in the model. Permissions are granted per operation, not as a convenient blanket grant.
Do not treat your system prompt as a secret. If a policy only holds because nobody knows the hidden context, it is not a control. It must not contain credentials and must never serve on its own as a security boundary for authorisation.
Include cost exhaustion in your risk assessment. Unbounded consumption is rarely part of classic security reviews and now sits at number 6.
Know the boundary to the Agentic Top 10. This list claims only the case where the model is a component of your application. The moment it becomes an actor, with tools and memory carried between sessions, the risk moves to the OWASP Agentic Top 10. A risk analysis that works through the LLM list alone has a gap when it comes to agentic systems.
Test against adaptive attackers. The document cites research in which static attacks had near zero success while adaptive attacks exceeded 90 percent against most of twelve recent defences.
Note on the source: This article draws on the document "OWASP Top 10 for LLM Applications 2026" (version 1.0) by the OWASP GenAI Security Project, published under CC BY-SA 4.0.