PentestingHere
Log in Join

Centers for Medicare & Medicaid Services - Public Bug Bounty Program 2026

Centers for Medicare & Medicaid Services - Public Bug Bounty Program 2026 on Bugcrowd · Bugcrowd Active

Official page

Scope

At a glance

  • Maximum payout: $7,000
  • Public disclosure: Not allowed
  • Managed by the platform: Yes
  • Safe harbour: Full

In scope

  • https://eua.cms.gov/
  • https://eua.cms.gov/efi
  • https://portal.cms.gov/
  • https://www.cms.gov/
  • https://cmsnationaltrainingprogram.cms.gov/
  • https://*nsa-idr.cms.gov
  • https://*qpp.cms.gov/
  • https://csscoperations.com/

Out of scope

  • *https://www.eqrs.cms.gov and all related subdomains, APIs, and supporting services.
  • *https://eua.cms.gov/euareporting/

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback