NIST 800-53 r5 · Controls catalogue · Family AC
AC-14Permitted Actions Without Identification or Authentication
Identify {{ insert: param, ac-14_odp }} that can be performed on the system without identification or authentication consistent with organizational mission and business functions; and Document and provide supporting rationale in the security plan for the system, user actions not requiring identification or authentication.
Last updated: 22 August 2026 14:14 UTC
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (1)
- T1137.002 Office Test Persistence
Weaknesses this control addresses (4)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Documenting permitted unauthenticated actions prevents missing authorization by making all exceptions explicit and subject to organizational review. |
CWE-284 | Improper Access Control | 6,900+ | Explicitly identifying and documenting actions permitted without identification or authentication enforces proper access control boundaries by defining justified exceptions. |
CWE-306 | Missing Authentication for Critical Function | 3,300+ | Requiring identification and rationale for actions allowed without authentication ensures critical functions are not left unprotected by forcing review of authentication requirements. |
CWE-285 | Improper Authorization | 1,500+ | The control's documentation requirement reduces improper authorization by ensuring only mission-justified actions bypass authentication. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-41405 | 5.9 | 7.5 | 0.0048 | good |
CVE-2026-11605 | 5.9 | 7.5 | 0.0052 | good |
CVE-2026-41374 | 4.5 | 5.3 | 0.0047 | good |
CVE-2026-41331 | 4.4 | 5.3 | 0.0030 | good |
CVE-2026-3592 UPD | 4.4 | 5.3 | 0.0041 | good |
CVE-2024-51567 KEV UPD | 10.0 | 10.0 | 0.8652 | good |
CVE-2025-32433 KEV UPD | 10.0 | 10.0 | 0.9859 | good |
CVE-2025-34028 KEV UPD | 10.0 | 10.0 | 0.9766 | good |
CVE-2024-5910 KEV UPD | 9.9 | 9.8 | 0.9178 | good |
CVE-2024-47575 KEV UPD | 9.9 | 9.8 | 0.9495 | good |
CVE-2024-0012 KEV UPD | 9.9 | 9.8 | 0.9970 | good |
CVE-2024-11680 KEV UPD | 9.9 | 9.8 | 0.9156 | good |
CVE-2025-3248 KEV UPD | 9.9 | 9.8 | 1.0000 | good |
CVE-2025-61757 KEV UPD | 9.9 | 9.8 | 0.8831 | good |
CVE-2026-24423 KEV UPD | 9.9 | 9.8 | 0.8769 | good |
CVE-2026-33017 KEV UPD | 9.9 | 9.8 | 0.9618 | good |
CVE-2026-39987 KEV UPD | 9.9 | 9.8 | 0.9658 | good |
CVE-2026-41940 KEV | 9.9 | 9.8 | 0.9811 | good |
CVE-2026-20253 KEV UPD | 9.9 | 9.8 | 0.9694 | good |
CVE-2026-35273 KEV | 9.9 | 9.8 | 0.9547 | good |
CVE-2026-72529 KEV | 9.9 | 9.8 | 0.0078 | good |
CVE-2024-46506 UPD | 9.7 | 10.0 | 0.6204 | good |
CVE-2025-0108 KEV UPD | 9.5 | 9.1 | 0.9846 | good |
CVE-2025-58434 UPD | 9.3 | 9.8 | 0.4989 | good |
CVE-2025-4008 KEV UPD | 9.2 | 8.8 | 0.9326 | good |