The German Chapter of the Open Worldwide Application Security Project (OWASP) holds its annual OWASP conference. We are pleased to announce that this year's event will be held in Karlsruhe on September 23-24, 2026!
The Conference Day on the 24th will feature presentations on various application security topics. On the preceding day, we are offering two formats this year:
The new OWASP Diversity PreCon is a free opportunity to explore and network. Especially women and queer individuals will have the chance to connect with the Application-Security-Community — directly, without complications, at eye level.
Additionally, as usual, we offer in-depth Trainings on selected security topics that are available for all interested participants.
The 23.09. will be concluded with a pre-evening event for all attendees.
On the main conference day (24.09.2026) a series of exciting technical and non-technical presentations in the field of application security will take place. On the previous day (23.09.2026) various seminars and an evening event for shared experience exchange and the new OWASP Diversity PreCon will be offered. For participation in the event you will receive up to 14 CPE continuing education credits.
| Uhrzeit | Topics 1 | Topics 2 |
|---|---|---|
|
09:00
|
Introduction |
|
|
10:00 - 12:30
|
Einführung ins Reverse Engineering von IoT-Firmware (Teil 1) |
Saftladen unter Beschuss |
KI-Security Hands-On: Prompt Injection & Co. selbst ausprobieren |
Cyber Resilience Act & DSGVO: TOMS als Schlüssel für Security-Compliance-Synergien |
|
|
12:30 - 13:30
|
Lunch Break |
|
|
13:30 - 14:30
|
Vielfalt von AppSec |
|
|
14:30 - 16:30
|
Einführung ins Reverse Engineering von IoT-Firmware (Teil 2) |
Saftladen unter Beschuss |
KI-Security Hands-On: Prompt Injection & Co. selbst ausprobieren |
Was kann schief gehen? Threat Modelling - Bedrohungsmodellierung für Einsteigerinnen. |
|
|
16:30
|
Closing Session |
|
| Time | Track 1 | Track 2 |
|---|---|---|
|
09:00 - 13:00
|
Understanding Modern Application Security - Foundations |
Scaling Threat Modeling with OWASP Precogly: Building AI-Agent-Ready Programs |
|
14:00 - 18:00
|
Hacking a smart Pizza Place with the OWASP AI Exchange - PwnzzAI! |
CANCELLED - Silent Sabotage: When AppSec Hits the Water — Exploiting the OWASP OT |
|
15:00 - 17:00
|
German Chapter Meeting |
|
|
from 18:30
|
Evening event in the Zieglersaal at Restaurant Akropolis |
| Time | Saal Baden | Saal Fidelitas | |
|---|---|---|---|
|
08:15 - 08:55
|
Registration |
||
|
08:55 - 09:05
|
Introduction |
||
|
09:05 - 09:50
|
Keynote: Rob van der Veer |
||
|
09:50 - 09:55
|
Split to track #1 and track #2 |
||
|
09:55 - 10:20
|
Agentic AI Gateway Enforcement of the OWASP Top 10 |
Understanding the Map of Threat Modeling Through the Lens of the TM-BOM |
|
|
10:20 - 10:45
|
Hackbots under control: Methodology for Autonomous Pentesters |
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis |
|
|
10:45 - 11:20
|
Break |
||
|
11:20 - 12:05
|
Indirect Prompt Injection in the Wild: An Empirical Study of Prevalence, Techniques, and Objectives |
Vier grüne Häkchen, trotzdem gehackt: Threat Modeling für KI-Agenten |
|
|
12:05 - 12:55
|
What LLMs Can Do in Pentesting and Code Security |
CRA effizient und nachhaltig umsetzen |
|
|
12:55 - 13:55
|
Lunch Break |
||
|
13:55 - 14:40
|
How To Become a Certified AI Security Professional |
Zeit für OAuth 2.1 - Security Best Practices als neuer Standard |
|
|
14:40 - 15:10
|
OWASP AISVS: Bringing Order to AI Security Chaos |
How To Fuzz for Logic Bugs? Building Effective Oracles - A Case Study on Site Isolation Bypass Bugs |
|
|
15:10 - 15:40
|
How to Hack "Read-Only" SQL MCP Servers Online (Fast) |
New OWASP Kubernetes Top 10 in Action and Explained |
|
|
15:40 - 16:10
|
Break |
||
|
16:10 - 16:55
|
Public Money, Public Containers |
16:10 - 16:45 Race Against The Workflows: Stealing GitHub Tokens from Docker Images |
|
|
16:55 - 17:20
|
Sicher in einen neuen Hafen -- Die Geschichte einer Migration in eine europäische Cloud |
16:45 - 17:20 Silent but Deadly: Reconstructing Undisclosed Security Vulnerabilities in Public Package Registries |
|
|
17:20 - 17:25
|
Back to track #1 |
||
|
17:25 - 17:45
|
Celebrating the 25th Anniversary of OWASP and the 22nd of German Chapter |
||
|
17:45 - 17:50
|
Chapter Lead: Thanks & meet you next year |
||
|
17:50 - 20:00
|
25 Years OWASP - CelebrationFollowing the German OWASP Day, there's something special in store. Let's celebrate 25 years of OWASP together! If you have the time and feel like it, just stick around after the official end of the event. Drinks and snacks will be served until around 8:00 p.m., and you'll have the chance to chat with the community. |
||
We anticipate approximately 200 participants from a range of industries. By sponsoring the German OWASP Day 2026, you will be making a strong statement:
Your support for this key event in the German-speaking Application Security community will significantly bolster your company's expert reputation.
Building on the positive feedback from previous years, we've created several attractive opportunities to maximize your visibility at the conference, alongside your presence online and in official materials.
Price (net): 1.500 €
Perks:
Items marked with * must be provided by the sponsor.
Price (net): 4.000 €
Perks:
All points of the Standard Sponsor Package apply to the Gold Sponsor plus the following:
Items marked with * must be provided by the sponsor.
All sponsorship revenue is used solely to cover the costs of the conference and the mission of the independent and non-profit OWASP Foundation (501c3 Not-For-Profit).
The German OWASP Day 2026 is a security conference focused on expert talks covering secure development, operations, testing, and organizational aspects related to web-based applications. Cross-disciplinary and non-technical topics are also encouraged. The conference is primarily intended for a German-speaking audience, though English presentations are welcome.
At this year's German OWASP day we'd again like to offer a few half day workshops (3-4 hours) for the community.
Here you find the Call for Presentations on 24.09.2026
Here you find the Call for Community Trainings on 23.09.2026
The OWASP Trainings and the Conference will take place at the IHK Haus der Wirtschaft, Lammstraße 13-17, in Karlsruhe.
We suggest using public transport for your travel:
The Diversity PreCon will take place at the queerKAstle, Karlsruher Zentrum für queere Vielfalt, Liebigstraße 10-12, 76135 Karlsruhe
We suggest using public transport for your travel:
The evening event will take place at the Zieglersaal im Restaurant Akropolis, Baumeisterstraße 18, 76137 Karlsruhe
We suggest using public transport for your travel:
OWASP is an independent, global community committed to making web application security more visible, sharing expertise in developing and operating secure web applications, and offering resources freely available to everyone. All OWASP materials, including documents, videos, slides, and podcasts, can be used for free under an open license.
OWASP is open, inclusive, and vendor-neutral. Everyone is welcome to contribute to projects or simply benefit from the shared knowledge. A great way to get involved is by attending the OWASP Meetups, which regularly take place in many major German cities.
For more details, visit the German OWASP Chapter website and follow us on social media.
Organisation
martina . hartmann [at] owasp . org
Organisation
kai [at] owasp . org
Organisation
christian . dresen [at] owasp . org
Organisation
christian . becker [at] owasp . org
Organisation
lilith . pendzich [at] owasp . org
Organisation
henrik . willert [at] owasp . org
Organisation
jasmin . mair [at] owasp . org
Organisation
dirk [at] owasp . org
Sponsoring
tobias . glemser [at] owasp . org