Prompt Injection Tops OWASP but Evades Scanners and Incident Rankings
OWASP ranks prompt injection first, but 6,639 incidents place it 12th, exposing blind spots in scans and the need for strict agent authorization gates.
Summary
Kyriakos “Rock” Lambros of Zenity and Steve Wilson of Exabeam published an exploratory arXiv study on August 18, 2026, not peer reviewed or an official OWASP release. They gathered 7,714 incidents, labeling 6,639 across 20 categories with Bayesian correction for classifier error. Prompt injection, OWASP’s No. 1 LLM risk for three years, ranked No. 12 in incidents. The rankings had no detectable agreement: Cohen’s kappa was 0.20, with a 90% interval from negative 0.16 to 0.57; only 29 practitioners formed the expert signal.
Prompt injection hides instructions in logs, tickets or retrieved documents, then makes an agent act through legitimate credentials, creating no defect or CVE. CrowdStrike found malicious prompts hit legitimate GenAI tools at more than 90 organizations in 2025, stealing credentials and cryptocurrency. Misinformation ranked No. 13 among experts and No. 2 in incidents, with 99% disagreement probability, although many records concern deepfakes and AI-generated harm rather than LLM flaws. Persistent memory poisoning ranked No. 4 versus No. 16, and MCP tool exploitation No. 7 versus No. 16; both had 6 to 20 intervals.
2026 CVEs include an 8.3 High KQL injection in Azure Data Explorer MCP Server, indirect prompt injection in Kong’s Konnect MCP Server, and a 10.0 Critical Ruflo flaw enabling shells, key theft and memory poisoning. OWASP’s August 4 GenAI LLM Top 10 2026 weighted 29 votes at 75% and incidents at 25%. Prompt injection stayed No. 1, misinformation rose two places, excessive agency reached No. 3, unbounded consumption No. 6, and improper output handling fell to No. 10. Ivanti found 87% prioritize agentic AI and 77% accept some action without review. CISOs should treat OWASP as a coverage map, test live systems, log model activity, gate authorization externally, and fund memory and MCP boundaries by business exposure.
Positives
- 7,714 incidents and 6,639 classified cases provide a substantial public dataset for comparing expert judgment with observed LLM security events.
- OWASP’s August 4, 2026 list incorporated incident evidence for the first time, assigning it 25% of the ranking weight.
- A four-model bake-off preserved the incident ordering at 0.918 Spearman correlation, while the engine and artifacts were published on GitHub.
- External authorization gates let agents investigate and propose bounded remediation without independently executing high-impact infrastructure changes.
- 2026 High and Critical CVEs for Azure Data Explorer, Kong Konnect and Ruflo provide concrete evidence for emerging MCP and memory risks.
Risks & concerns
- Cohen’s kappa of 0.20, with a 90% interval from negative 0.16 to 0.57, showed no statistically detectable agreement between experts and incidents.
- Classifier precision ranged from 93% to 13%, four categories fell below 50%, and roughly 38% of the gold set was actually out of scope.
- One reviewer adjudicated all 1,200 gold-set incidents and overrode model consensus on 553, preventing measurement of agreement between annotators.
- Prompt injection can exploit valid agent credentials without producing a product defect or CVE, leaving conventional vulnerability scanners blind.
- Persistent memory poisoning and MCP exploitation each had incident intervals spanning 14 ranking positions, making their public records too thin for confident placement.
- 77% of security teams report some comfort with AI acting without human review despite unresolved disagreement over agentic AI risk priorities.
