MITRE ATLAS 2026.09 / technique reference

AML.T0132
Misconfigured or Publicly Exposed AI Services

← Back to the ATLAS matrix · Official MITRE definition

MITRE source definition

AI agents and LLM platforms are deployed across diverse architectures, including standalone servers, SaaS platforms, and low-code builders. All of these often have misconfigured access controls, ranging from missing authentication in LLM runtimes to permissive public access settings, that significantly expand their attack surface.

AI agent's security posture affects how attackers are able to explore which agentic attack surface is available to them and directly either expands or limits an adversary's ability to discover and interact with a target's AI agents. For example, one internet-facing AI service could be more easily discoverable by any unauthenticated user, while another may require compromised credentials to even be discovered.

Adversaries may discover and interact with AI agents and LLM services as unauthenticated users via a combination of various OSINT and active scanning methods. These could include using search engines to discover accessible agentic deployments (See [Search Open Technical Databases](/techniques/AML.T0000)), search backlinks which could indicate existing or open agents which have been embedded to frontends (See [Search Open Website/Domains](/techniques/AML.T0095)), or directly scanning a target's AI infrastructure (See [Active Scanning](/techniques/AML.T0006)).

Source modified 2026-09-15. Reproduced from the pinned ATLAS release; inline technique links resolve to local reference pages.

No explicit relationship in this pinned source.

Source-backed defensive context

MITRE mitigations

MITRE case studies

These are explicit source relationships, not independently reproduced incidents or validated detection coverage.

Simulation and telemetry boundary

This is a technique reference page, not a runnable simulation. No ATLAS-specific telemetry mapping, local attack execution or detector validation is asserted. MITRE maturity describes its source evidence, not a 1200km lab result.

For broader context—not technique-specific control mappings—see AI Security, AI Security Course, and detection-validation methodology.

Provenance and attribution

Immutable MITRE ATLAS source · Import provenance · Attribution and transformation notice · Apache License 2.0

Copyright 2021-2026 MITRE. Source text and explicit relationships are retained; navigation, formatting and local links are provided by 1200km.

No explicit relationship in this pinned source.