TIER 1 · VULNERABILITY CATALOGUE

OWASP Top 10 for LLMs to AITBM Mapping

Routes the released OWASP LLM risks to AITBM tests and evidence without assigning generic risk scores.

How to use this crosswalk

External requirements, controls, threats, and practices identify evidence to collect or tests to run. Only measured evidence from the assessed deployment determines AITBM rubric placements, IVP, ORP, ACI, MVT findings, and ERS.

Mapping content last verified 2026-08-13. No endorsement by the external framework owner is implied.

OWASP Top 10 for LLMs

Vulnerability catalogue

OWASP Top 10 for LLM Applications 2026 · OWASP GenAI Security Project

The released 2026 list changes the meaning and order of LLM03–LLM10 and introduces Hidden Context Exposure at LLM08. AITBM maps each current risk to evidence and test-selection targets; no risk class has an inherent AITBM anchor or generic ERS.

OWASP LLM Risk Primary AITBM Sub-Metrics Evidence Use / Notes
LLM01 Prompt InjectionRo-1; Cn-1, Cn-2, Cn-3, Cn-6Injection, authority-escape, release-gate, and irreversible-action tests
LLM02 Sensitive Information DisclosurePr-1, Pr-2, Pr-3, Pr-4; Cn-3Leakage, inference, minimization, re-identification, and release evidence
LLM03 Excessive AgencyCn-1, Cn-2, Cn-5, Cn-6, Cn-7; AaAuthority, identity, approval, reversibility, budget, and autonomy evidence
LLM04 Supply ChainTr-4, Ro-4; ACI Pc; As, RfArtifact, dependency, provenance, supplier, and remediation evidence
LLM05 Data and Model PoisoningRo-4, Ro-2, Fa-3, Tr-3, Tr-4Release-bound poisoning, drift, representation, trace, and lineage tests
LLM06 Unbounded ConsumptionCn-7; As, AaBEC, RBVR, LTFR, GDSR, and deployment-context evidence
LLM07 MisinformationRo-3, Tr-1, Tr-2; Cn-3Factuality, consistency, explanation, calibration, and release validation
LLM08 Hidden Context ExposurePr-1, Cn-1, Cn-3; Tr-3Hidden-context extraction, deterministic access control, release, and audit tests
LLM09 Vector and Embedding WeaknessesRo-4, Pr-2, Pr-3, Pr-4, Cn-1; Tr-3, Tr-4Inversion, membership, poisoning, segregation, lifecycle, and provenance tests
LLM10 Improper Output HandlingCn-3, Cn-1, Cn-6; Ro-1Sanitization, schema, sink-authorization, isolation, and action-gate tests

Key findings

  • All ten 2026 risks have a current evidence path; 2025 identifiers and generic risk-class ERS values are not carried forward.
  • LLM06 Unbounded Consumption maps directly to Cn-7 aggregate resource and loop-containment measurements, while Aa and As remain deployment-specific.
  • LLM08 Hidden Context Exposure never treats system-prompt secrecy as authorization; deterministic access and output controls must be tested independently.
  • Fairness remains only partially represented in the Top 10, so applicable Fa-1–Fa-4 testing remains independent.

OWASP Top 10 for LLMs 2026 reference →