OWASP Top 10 for Agentic Applications 2026
ASI03 Identity and Privilege Abuse
Agents act with borrowed, over-scoped, or long-lived credentials, so a compromised agent inherits far more access than its task needs.
Categories that mitigate it
- Agent identity and credentials
- Delegated and user-to-agent auth
- Agent authorization and fine-grained policy
Vendors that say they address it
Only vendors that publish their own mapping to this threat are listed.
- LakeraAcquired by Check Point38
Runtime guardrails for LLM applications and agents (Lakera Guard) that screen prompts, tool responses, and tool descriptions for injection and data leakage, plus AI red teaming. Acquired by Check Point in 2025.
- PromptfooBeing acquired by OpenAI31
Open-source red teaming, static scanning, and evaluation for LLM applications and agents, with plugins for tool misuse, MCP, memory poisoning, and prompt injection. OpenAI agreed to acquire it in March 2026 and committed to keep it open source.