"Agentic Posture Vulnerability": A Vulnerability-Management Record for Agent Exposures That Have No CVE
arXiv 2608.05884 (Aug 6) proposes the agentic posture vulnerability (APV) as a task-conditioned abstraction for security programs that need to track persistent deployed agent instances spanning multiple components and outliving any single incident. One posture can produce different runtime manifestations across tasks; an APV links those manifestations to the invariant posture and stays open until authority is narrowed, a missing control is added, risk is accepted, or closure is verified. The paper distinguishes APVs from CVE-addressable product defects, OWASP Excessive Agency, and the runtime authorization-execution gap, and supplies six recurring patterns, a lifecycle, a minimum record schema, and a control-and-closure matrix — usable today as a template if you're trying to file agent permission sprawl somewhere other than a wiki page.
↳ Follow the thread