By NHI Mgmt Group Editorial TeamBased on Lasso Security: “OWASP Top 10 for Agentic Applications” (March 4, 2026)

TL;DR: OWASP’s 2026 Top 10 for Agentic Applications maps the highest-impact failure modes in agentic systems, including goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, and rogue behaviour across autonomous workflows, according to Lasso Security. Traditional AppSec, DLP, and cloud controls were not designed for agents that plan, act, and mutate state at runtime.


At a glance

What this is: This is Lasso Security’s analysis of OWASP’s 2026 Top 10 for Agentic Applications, showing that agentic systems create a new attack surface spanning goals, tools, identity, memory, communication, and runtime behaviour.

Why it matters: It matters because IAM, PAM, and application security programmes built for static software do not adequately govern autonomous agents that can select actions, call tools, and change state during execution.


Context

Agentic applications are software systems that can plan, choose tools, and act across multiple steps instead of simply returning a response. That changes the security problem from protecting a single request to governing a runtime decision process that can be steered, poisoned, or misused mid-execution.

For identity teams, the issue is not only model safety but delegated authority. When agents inherit credentials, interact with APIs, and coordinate with humans or other agents, existing access models assume more determinism than the system actually has.

OWASP’s 2026 Top 10 for Agentic Applications gives the field a shared vocabulary for these failures. The article frames the current state as typical for early production adoption: capability has moved faster than control design.


Key questions

Q: What breaks when agentic systems inherit broad application credentials?

A: Broad credentials create a runtime delegation gap because the system can use the same access for multiple actions that were never individually approved. That makes audit, containment, and revocation harder. The issue is not authentication failure, but excessive authority combined with unpredictable execution paths.

Q: How should security teams validate ransomware defenses against privilege abuse and lateral movement before an attack lands?

A: Security teams should test the full kill chain, not just perimeter blocking. Focus on whether privileged credentials, remote execution paths, scheduled tasks, domain policy abuse, and backup protection controls can be chained together. The goal is to see whether detection and containment still work after an attacker has already obtained high-value access. That kind of validation exposes gaps that checklist reviews usually miss.

Q: What are the signs that agent memory or context is being poisoned?

A: Look for repeated bad recommendations, sudden shifts in tool selection, inconsistent task memory, or outputs that reference instructions the operator never approved. Those signals suggest that the agent is carrying forward untrusted context into later sessions, which can bias decisions long after the original injection.

Q: How should security teams govern Agent2Agent communication in production?

A: Treat every agent as a governed non-human identity, not just a service integration. Require ownership, scoped authentication, traceable task IDs, and lifecycle offboarding before the first production workflow goes live. If an agent can discover peers and request access at runtime, it belongs inside identity governance and audit processes.


Technical breakdown

Agent goal hijacking and planning drift

Agent goal hijacking occurs when an attacker changes what the agent believes it is trying to achieve, often through malicious prompts, compromised intermediate tasks, or manipulation of planning steps. In an agentic system, the goal is not just a message to the model. It becomes the organising principle for downstream tool calls, state updates, and hand-offs. Once the goal is redirected, every subsequent action can look internally consistent while still serving the attacker. This is why agentic risk is different from ordinary prompt injection. The attack survives because the agent continues executing a coherent plan that is no longer aligned to the business intent.

Practical implication: bind agent objectives to explicit task boundaries and verify that downstream actions still match the approved business intent.

Tool misuse, privilege abuse, and external APIs

Agentic systems often operate with access to browsers, APIs, file systems, RPA workflows, and other operational tools. Tool misuse happens when an attacker influences how those tools are invoked, while identity and privilege abuse occurs when the agent inherits credentials or tokens that exceed the task it is performing. The combination is dangerous because a compromised agent can do real work, not just produce unsafe text. The article’s core warning is that trust is inherited through the tool chain. If the agent can call a sensitive API with standing privilege, the security boundary has already moved away from the model and into its delegated authority.

Practical implication: segment tool permissions per task and separate agent identity from human or service-account credentials wherever possible.

Memory poisoning and inter-agent trust failures

Memory poisoning targets long-term memory, scratchpads, retrieval layers, and agent-to-agent communication paths. Unlike a one-time prompt attack, poisoned memory persists and can influence future sessions, which makes the compromise durable even after the original input is gone. In multi-agent environments, insecure inter-agent communication extends the problem because one spoofed or intercepted message can propagate bad state across the system. The article shows why runtime trust in agent ecosystems must be treated as a governed channel, not a casual coordination layer. Persistent state and unauthenticated messaging create opportunities for repeated manipulation rather than one-off misuse.

Practical implication: authenticate agent-to-agent messaging and treat persistent memory as an attack surface that needs validation, not just storage.


Threat narrative

Attacker objective: The attacker aims to turn an agent’s own delegated authority into a scalable execution channel for unauthorised actions, lateral influence, and operational damage.

  1. Entry occurs through malicious prompts, compromised subtasks, poisoned memory, or weakly validated inter-agent messages that influence how the agent interprets its objective.
  2. Credential or authority abuse follows when the agent uses inherited credentials, tokens, APIs, or tools under a hijacked or expanded task scope.
  3. Impact emerges when the agent executes unauthorised actions, repeats poisoned behaviours, or propagates bad state across workflows and connected agents.
  • Meta Muse agent hijack 2026: An undocumented Muse setting let local malware hijack Meta's personal AI agent, steal its authentication material and abuse user access.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Agentic security breaks the assumption that access is static long enough to be governed after the fact: access review, recertification, and conventional entitlement controls were built for privileges that persist across time. When an agent can acquire, use, and mutate authority inside a single runtime session, the governance object changes from standing access to execution-time behaviour. The implication is that identity programmes must treat runtime decision paths as first-class control boundaries.

Identity and privilege abuse is the central governance problem in agentic systems: the article shows that agents often inherit human or system credentials and then operate across tools that were never designed for autonomous reuse. That collapses the separation between the actor and its delegated authority. The practical conclusion is that agent identity needs explicit lifecycle, scope, and accountability rules, not just model safety checks.

Memory poisoning creates identity persistence without administrative visibility: long-term memory and retrieval layers can preserve attacker influence after the initial prompt or message is gone. That means the security problem is no longer just preventing a bad instruction, but governing what the agent remembers and reuses. Practitioners should view persistent memory as an identity-bearing control plane, not a convenience feature.

Tool orchestration is now an authorisation surface, not just an integration pattern: every API call, browser action, or workflow invocation can become a privilege amplifier when the agent decides sequencing at runtime. Traditional AppSec and DLP controls assume more predictable request paths than agentic systems provide. The field now needs controls that understand delegated action, not only data flow.

Identity blast radius: the article’s most useful concept is that an agent’s compromise should be measured by how far its delegated trust can spread across tools, memory, and connected agents. That is the right unit of analysis for governance because the harm is not confined to one prompt or one model response. Teams should design around contained blast radius, not isolated model hardening.

From our research library:

What this signals

Identity blast radius: agentic risk is best measured by how far delegated trust can spread across tools, memory, and connected agents. That framing is more useful than asking whether a model is merely “safe”, because the operational question is how much damage a compromised runtime can propagate before human review catches up.

Security teams should expect agent governance to move from policy documents to execution-time controls. The practical shift is toward task-scoped identities, authenticated inter-agent traffic, and stateful memory review, because the attack surface is created by runtime delegation rather than by static application code.


For practitioners

  • Map every agent to a named identity owner Assign a human owner to each agent, document the business task it is allowed to perform, and record the credentials, APIs, and external services it can reach. This closes the gap between informal experimentation and governed production use.
  • Separate agent credentials from human accounts Issue agent-specific credentials with narrowly scoped permissions and avoid letting agents inherit broad human access or shared service tokens. That reduces privilege abuse when the agent is manipulated or behaves unexpectedly.
  • Constrain tool use to approved action paths Define which tools an agent may call for each workflow stage and validate that tool selection stays within that stage. Where possible, enforce policy checks before external APIs, browsers, or file operations are invoked.
  • Treat persistent memory as governed state Review what the agent stores, retrieves, and reuses across sessions, then classify that memory as an input to access decisions rather than a neutral convenience layer. Poisoned memory should be removable and auditable.
  • Test for rogue behaviour before production use Use red-team and purple-team exercises to probe goal hijacking, tool misuse, and inter-agent spoofing under realistic task conditions. Focus on what the agent does when prompts, tools, and state are simultaneously manipulated.

Key takeaways

  • Agentic applications create a new control problem because they can plan, act, remember, and coordinate at runtime with delegated authority.
  • The main failure modes in the article are goal hijacking, tool misuse, privilege abuse, memory poisoning, and rogue behaviour across agent workflows.
  • Practitioners should govern agent identity, constrain tool access, and treat persistent memory and inter-agent messaging as security-relevant state.

Key terms

  • Agent Goal Hijack (ASI01): An attack where an adversary redirects an AI agent's objectives by manipulating its instructions, tool outputs, or external content, causing it to act outside its intended scope while appearing normal. The number one risk in the OWASP Top 10 for Agentic Applications 2026.
  • Tool Misuse: Tool misuse occurs when an agent uses an allowed integration in a way that exceeds its intended task, scope, or risk tolerance. The problem is often not access alone but the combination of valid credentials, broad permissions, and unbounded action sequencing.
  • Memory Poisoning (ASI06): An attack where malicious content is injected into an AI agent's memory or context, causing it to alter its behaviour in subsequent tasks, potentially exfiltrating secrets, escalating privileges, or acting against its intended purpose.
  • Inter-Agent Context: Inter-agent context is the data, prompts, memory, or task state passed from one AI agent to another. It can improve delegation, but it also creates exposure if too much sensitive information is forwarded across different permissions, clouds, applications, or trust boundaries. Minimizing context reduces unnecessary spread.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org