NIST 800-53 r5 · Controls catalogue · Family AC
AC-24Access Control Decisions
{{ insert: param, ac-24_odp.01 }} to ensure {{ insert: param, ac-24_odp.02 }} are applied to each access request prior to access enforcement.
Last updated: 22 August 2026 07:11 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 1 mapping(s) from 1 framework(s): OWASP-Web 1 (partial)
Implementations targeting this control (0)
- No implementations targeting this control yet.
ATT&CK techniques this control mitigates (0)
- No ATT&CK techniques mapped to this control yet.
Weaknesses this control addresses (6)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-862 | Missing Authorization | 10,200+ | Requiring a decision for every access request prevents missing authorization checks that would otherwise allow unauthorized access. |
CWE-284 | Improper Access Control | 6,900+ | Ensuring access control decisions are made and applied to every request before enforcement directly prevents improper access control by requiring policy-based checks. |
CWE-863 | Incorrect Authorization | 3,900+ | Applying decisions to each request prior to enforcement mitigates incorrect authorization by enforcing consistent policy evaluation. |
CWE-639 | Authorization Bypass Through User-Controlled Key | 2,500+ | Per-request decision making makes it harder to bypass authorization using user-controlled keys without proper validation in the decision process. |
CWE-285 | Improper Authorization | 1,500+ | The control mandates authorization decisions for each access request, reducing the ability to exploit improper authorization weaknesses. |
CWE-425 | Direct Request ('Forced Browsing') | 200+ | Forcing a decision on every access request, including direct ones, reduces the exploitability of forced browsing by ensuring no unchecked access paths. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2025-48827 UPD | 9.9 | 10.0 | 0.7746 | good |
CVE-2025-29927 UPD | 9.5 | 9.1 | 0.9928 | good |
CVE-2024-58136 KEV UPD | 8.9 | 9.0 | 0.8464 | good |
CVE-2024-24116 UPD | 8.8 | 9.8 | 0.2841 | partial |
CVE-2024-45387 UPD | 8.8 | 9.9 | 0.4184 | good |
CVE-2025-48828 UPD | 8.6 | 9.0 | 0.6040 | good |
CVE-2026-21509 KEV UPD | 8.5 | 7.8 | 0.7215 | good |
CVE-2026-21514 KEV | 8.5 | 7.8 | 0.0152 | good |
CVE-2024-34257 UPD | 7.8 | 9.8 | 0.0382 | good |
CVE-2026-10580 UPD | 7.8 | 9.8 | 0.0295 | good |
CVE-2024-36130 UPD | 7.7 | 9.8 | 0.0225 | good |
CVE-2023-50780 UPD | 7.7 | 8.8 | 0.1698 | good |
CVE-2025-21400 | 7.7 | 8.0 | 0.3449 | good |
CVE-2025-20125 UPD | 7.6 | 9.1 | 0.1674 | good |
CVE-2025-29659 UPD | 7.6 | 9.8 | 0.0141 | good |
CVE-2025-49827 UPD | 7.6 | 9.8 | 0.0140 | good |
CVE-2025-31255 UPD | 7.6 | 9.8 | 0.0157 | good |
CVE-2025-30392 UPD | 7.5 | 9.8 | 0.0104 | good |
CVE-2025-65041 UPD | 7.5 | 10.0 | 0.0078 | good |
CVE-2026-32213 UPD | 7.5 | 10.0 | 0.0091 | good |
CVE-2026-33105 UPD | 7.5 | 10.0 | 0.0072 | good |
CVE-2026-7473 KEV UPD | 7.5 | 5.8 | 0.0111 | partial |
CVE-2024-32881 UPD | 7.4 | 9.8 | 0.0080 | good |
CVE-2024-36108 UPD | 7.4 | 9.8 | 0.0063 | good |
CVE-2024-5699 UPD | 7.4 | 9.8 | 0.0077 | partial |