Skip to content

OWASP Top 10 for Agentic Applications 2026

ASI03 Identity and Privilege Abuse

Agents act with borrowed, over-scoped, or long-lived credentials, so a compromised agent inherits far more access than its task needs.

OWASP source

Categories that mitigate it

Vendors that say they address it

Only vendors that publish their own mapping to this threat are listed.

Incidents