Work at Zendesk Managed Bug Bounty Engagement? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
Reviews
0 publishedNo reviews yet.
Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.
Zendesk is the complete customer service platform, powered by AI. Equip your agents with powerful AI tools and workflows that boost efficiency and elevate customer experiences across every channel. Ratings/Rewards and Bounty Rules: For the initial prioritisation/rating of findings, this program will use the BugCrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Access The targets within scope are publicly accessible. Credentials All research must be conducted using your own Zendesk instance which you can sign up for here. When asked for an email, please provide your @bugcrowdninja.com email address. When asked for your company name, please use the following: bb-<bugcrowd-username> In cases where you need to create additional accounts or need to test beyond the trial period, please increment your company name with an appropriate integer or date-based string Your account should end up with a domain name that looks like bb-acidburn-01.zendesk.com
Scope
12 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Zendesk AI | website | ✓ bounty | not set |
| Zendesk Front End | website | ✓ bounty | not set |
| Zendesk Marketplace Apps created by Zendesk | website | ✓ bounty | not set |
| Zendesk Mobile Applications | other | ✓ bounty | not set |
| Zendesk Public Repositories | other | ✓ bounty | not set |
Show all 12 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| Zendesk Suite | website | ✓ bounty | not set |
| \*.zdassets.com | other | out | not set |
| Already public vulnerabilities (i.e. CVE’s) in infrastructure, frameworks or libraries we use | other | out | not set |
| support.zendesk.com | other | out | not set |
| www.zendesk.com | other | out | not set |
| Zendesk for Sales or Zendesk Sell | other | out | not set |
| Zendesk supply chain, vendors and contractors | other | out | not set |