Work at Centers for Medicare & Medicaid Services - Public Bug Bounty Program 2026? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Purpose: The goal of the 2026 CMS Bug Bounty is to improve the security posture of CMS information systems by proactively identifying and mitigating vulnerabilities prior to adversarial exploitation through monetary incentives for security research. This engagement invites security researchers to mimic hacker behavior to identify and report on vulnerabilities in select CMS systems. This approach provides an additional layer of scrutiny beyond CMS’ internal security tools and practices. Researchers with diverse expertise also apply new, innovative and different methods to identifying vulnerabilities. Researcher Restrictions: This is a public program. Anyone may submit vulnerabilities for consideration, but bounty payments are subject to eligibility requirements. CMS and the vendor (Bugcrowd) do not conduct background checks. Instead, eligibility is enforced through sanctions screening, platform restrictions, researcher attestation, and payout controls. By participating in this engagement, you agree to the terms contained in this Rules of Engagement (ROE) prior to engaging in authorized security research conducted under the CMS program, including but not limited to the restrictions listed below: Citizenship: While security researchers are not required to have U.S. citizenship, they may not hold citizenship from, or reside in the following countries: Afghanistan, Central African Republic, China, Cuba, Cyprus, Democratic Republic of Congo, Eritrea, Haiti, Iran, Iraq, Lebanon, Libya, North Korea, Russia, Somalia, South Sudan, Sudan, Syria, or Zimbabwe. Watch List: Researchers may not appear on the U.S. Treasury’s “Specially Designated Nationals” (SDN) list and may be vetted by the DHS National Targeting Center. Criminal Background: Researchers may not have been convicted of a misdemeanor or felony and must be cleared by the vendor per the vendor’s policies and practices. Experience: Researchers of all levels of experience are welcome. Affiliation: If a current Federal employee or contractor, researchers may need Counsel consultation and approval. Current CMS Federal employees and contractors may not participate in the 2025 CMS Bug Bounty. Equipment: Must be done on personally owned devices. Skills: Researchers must possess the knowledge, skills, and abilities most applicable and valuable for the goals of the engagement and the specific assets and areas of focus. Ratings/Rewards: To be eligible for rewards, all reports must include a POC that can be replicated by authorized Bugcrowd and CMS personnel. All information required to reproduce each vulnerability must be submitted prior to the program closing. Any reports requiring more information after the program has ended will not be considered for a reward. CMS will evaluate the plausibility, existence, and status of vulnerabilities submitted for bounties and reserves the right to make all decisions regarding vulnerability validity, status, and eligibility for bounty payment. CMS reserves the right to end the payment of bounties at any time. Bounty awards will be prioritized based on the submission timestamp for the initial instance of each unique vulnerability. Findings already documented or known to the CMS team will not be eligible for bounty payments. Duplicates: Researchers are encouraged to report all vulnerabilities that they find and to re- test after CMS has remediated the issue. Additional bounties will not be awarded for retesting the same vulnerability unless new or related issues are discovered. Vulnerabilities that share the same root cause and affect multiple sections or areas of a website will be treated as duplicates. In such cases, only the first instance of the vulnerability will be eligible for a bounty, though reporting additional instances is still encouraged to support comprehensive remediation efforts. A global fix is recommended to address the root cause across all affected sections. For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Bounty Table The bounty for each vulnerability is set on a sliding scale according to criticality. Priority Impact Vulnerability Examples Bounty Amount P1 Provide proof that a vulnerability is present on an in-scope asset Command Injection, SQL Injection, Remote Code Execution $5,000 - $7,000 P2 Provide proof that a vulnerability is present on an in-scope asset Directory Traversal, Poor Encryption Standards $2,500 - $3,500 P3 Provide proof that a vulnerability is present on an in-scope asset Reflective XXS with impact, Direct Object Reference, URL Redirect, CSRF with impact $1,000 - $2,500 P4 Provide proof that a vulnerability is present on an in-scope asset SSL Misconfigurations with little impact, SPF configuration problems, XSS with limited impact, CSRF with limited impact $250 - $500
Scope
8 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| █████████████ | website | ✓ bounty | not set |
| ████████████████ | website | ✓ bounty | not set |
| ████████████████████ | website | ✓ bounty | not set |
| ███████████████████████ | website | ✓ bounty | not set |
| ███████████████████████████ | website | ✓ bounty | not set |
Show all 8 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| ███████████████████████████████████████████ | website | ✓ bounty | not set |
| ██████████████████████████████████ | website | out | not set |
| ████████████████████████████████████████████████████████████████████████████████████ | website | out | not set |
Bugcrowd lists 10 scope entries; its public listing groups many assets under one label, so identical entries are shown once.