Cyber Posture

NIST 800-53 r5 · Controls catalogue · Family AC

AC-6Least Privilege

Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to accomplish assigned organizational tasks.

Last updated: 09 May 2026 03:25 UTC

Implementations targeting this control (4)

ATT&CK techniques this control mitigates (268)

Weaknesses this control addresses (8)AI

CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.

CWE Name CVEs Why this control addresses it
CWE-284Improper Access Control4,832Supports proper access control through restriction to only authorized necessary accesses.
CWE-269Improper Privilege Management2,907Implements core proper privilege management by restricting to only required rights.
CWE-732Incorrect Permission Assignment for Critical Resource1,824Prevents overly permissive assignments to critical resources by limiting to task needs.
CWE-276Incorrect Default Permissions1,757Guides setting of default permissions to the minimum required level.
CWE-285Improper Authorization1,230Requires authorization to grant only the minimal privileges needed for tasks.
CWE-266Incorrect Privilege Assignment826Ensures privileges are assigned only as necessary rather than incorrectly over-granted.
CWE-250Execution with Unnecessary Privileges305Directly prevents execution with more privileges than needed for assigned tasks.
CWE-272Least Privilege Violation25Enforces the least privilege principle to avoid violations of minimal necessary access.

Top CVEs where this control is the strongest mitigation

CVE Risk CVSS EPSS Match
CVE-2024-57726 KEV6.99.90.4916good
CVE-2015-101394.78.80.4855good
CVE-2026-33825 KEV3.97.80.0485good
CVE-2024-577782.48.80.1138good
CVE-2026-318522.010.00.0012good
CVE-2026-267252.09.80.0023good
CVE-2025-135632.09.80.0004good
CVE-2024-122842.08.80.0424good
CVE-2025-342742.09.80.0082good
CVE-2026-329222.09.90.0028good
CVE-2025-626452.09.90.0021good
CVE-2025-311942.09.80.0048good
CVE-2026-252122.09.90.0006good
CVE-2024-360462.09.80.0026good
CVE-2022-415722.09.80.0024good
CVE-2025-136192.09.80.0019good
CVE-2025-89002.09.80.0018good
CVE-2025-345152.09.80.0016good
CVE-2025-115332.09.80.0021good
CVE-2025-01802.09.80.0033good
CVE-2025-332232.09.80.0017good
CVE-2025-135382.09.80.0018good
CVE-2026-48802.09.80.0014good
CVE-2025-135422.09.80.0015good
CVE-2025-135402.09.80.0018good

Other controls in family AC

AC-1 AC-10 AC-11 AC-12 AC-13 AC-14 AC-15 AC-16 AC-17 AC-18 AC-19 AC-2 AC-20 AC-21 AC-22 AC-23 AC-24 AC-25 AC-3 AC-4 AC-5 AC-7 AC-8 AC-9