{"id":"ed4ad48a-148c-462f-84af-0356fb47ffd1","engagementId":"393a6116-c6d7-42e7-9de5-6e4e7e85627c","data":{"brief":{"id":"189ab622-08b7-4576-9df5-c13223eda1f1","name":"Centers for Medicare \u0026 Medicaid Services - Public Bug Bounty Program 2026","tagline":"CMS serves the public as a trusted partner and steward, dedicated to advancing health equity, expanding coverage, and improving health outcomes. ","description":"\u003ch2\u003ePurpose:\u003c/h2\u003e\n\n\u003cp\u003eThe goal of the 2026 CMS Bug Bounty is to improve the security posture of CMS information systems by proactively identifying and mitigating vulnerabilities prior to adversarial exploitation through monetary incentives for security research. \u003c/p\u003e\n\n\u003cp\u003eThis engagement invites security researchers to mimic hacker behavior to identify and report on vulnerabilities in select CMS systems. This approach provides an additional layer of scrutiny beyond CMS’ internal security tools and practices. Researchers with diverse expertise also apply new, innovative and different methods to identifying vulnerabilities.\u003c/p\u003e\n\n\u003ch2\u003eResearcher Restrictions:\u003c/h2\u003e\n\n\u003cp\u003eThis is a public program. Anyone may submit vulnerabilities for consideration, but bounty payments are subject to eligibility requirements. CMS and the vendor (Bugcrowd) do not conduct background checks. Instead, eligibility is enforced through sanctions screening, platform restrictions, researcher attestation, and payout controls. \u003c/p\u003e\n\n\u003cp\u003eBy participating in this engagement, you agree to the terms contained in this Rules of Engagement (ROE) prior to engaging in authorized security research conducted under the CMS program, including but not limited to the restrictions listed below:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCitizenship: While security researchers are not required to have U.S. citizenship, they may not hold citizenship from, or reside in the following countries: Afghanistan, Central African Republic, China, Cuba, Cyprus, Democratic Republic of Congo, Eritrea, Haiti, Iran, Iraq, Lebanon, Libya, North Korea, Russia, Somalia, South Sudan, Sudan, Syria, or Zimbabwe.\u003c/li\u003e\n\u003cli\u003eWatch List: Researchers may not appear on the U.S. Treasury’s “Specially Designated Nationals” (SDN) list and may be vetted by the DHS National Targeting Center.\u003c/li\u003e\n\u003cli\u003eCriminal Background: Researchers may not have been convicted of a misdemeanor or felony and must be cleared by the vendor per the vendor’s policies and practices.\u003c/li\u003e\n\u003cli\u003eExperience: Researchers of all levels of experience are welcome.\u003c/li\u003e\n\u003cli\u003eAffiliation: If a current Federal employee or contractor, researchers may need Counsel consultation and approval. Current CMS Federal employees and contractors may not participate in the 2025 CMS Bug Bounty.\u003c/li\u003e\n\u003cli\u003eEquipment: Must be done on personally owned devices.\u003c/li\u003e\n\u003cli\u003eSkills: Researchers must possess the knowledge, skills, and abilities most applicable and valuable for the goals of the engagement and the specific assets and areas of focus.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eTo be eligible for rewards, all reports must include a POC that can be replicated by authorized Bugcrowd and CMS personnel.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eAll information required to reproduce each vulnerability must be submitted prior to the program closing. Any reports requiring more information after the program has ended will not be considered for a reward.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eCMS will evaluate the plausibility, existence, and status of vulnerabilities submitted for bounties and reserves the right to make all decisions regarding vulnerability validity, status, and eligibility for bounty payment. CMS reserves the right to end the payment of bounties at any time. Bounty awards will be prioritized based on the submission timestamp for the initial instance of each unique vulnerability. \u003c/p\u003e\n\n\u003cp\u003eFindings already documented or known to the CMS team will not be eligible for bounty payments.\u003c/p\u003e\n\n\u003cp\u003eDuplicates: Researchers are encouraged to report all vulnerabilities that they find and to re- test after CMS has remediated the issue. Additional bounties will not be awarded for retesting the same vulnerability unless new or related issues are discovered. Vulnerabilities that share the same root cause and affect multiple sections or areas of a website will be treated as duplicates. In such cases, only the first instance of the vulnerability will be eligible for a bounty, though reporting additional instances is still encouraged to support comprehensive remediation efforts. A global fix is recommended to address the root cause across all affected sections.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eBounty Table\u003c/h2\u003e\n\n\u003cp\u003eThe bounty for each vulnerability is set on a sliding scale according to criticality.\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePriority\u003c/th\u003e\n\u003cth\u003eImpact\u003c/th\u003e\n\u003cth\u003eVulnerability Examples\u003c/th\u003e\n\u003cth\u003eBounty Amount\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003eProvide proof that a vulnerability is present on an in-scope asset\u003c/td\u003e\n\u003ctd\u003eCommand Injection, SQL Injection, Remote Code Execution\u003c/td\u003e\n\u003ctd\u003e$5,000 - $7,000\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003eProvide proof that a vulnerability is present on an in-scope asset\u003c/td\u003e\n\u003ctd\u003eDirectory Traversal, Poor Encryption Standards\u003c/td\u003e\n\u003ctd\u003e$2,500 - $3,500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003eProvide proof that a vulnerability is present on an in-scope asset\u003c/td\u003e\n\u003ctd\u003eReflective XXS with impact, Direct Object Reference, URL Redirect, CSRF with impact\u003c/td\u003e\n\u003ctd\u003e$1,000 - $2,500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003eProvide proof that a vulnerability is present on an in-scope asset\u003c/td\u003e\n\u003ctd\u003eSSL Misconfigurations with little impact, SPF configuration problems, XSS with limited impact, CSRF with limited impact\u003c/td\u003e\n\u003ctd\u003e$250 - $500\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e","industryTagId":null,"targetsOverview":"\u003cp\u003eCMS will provide financial incentives for the above listed systems of CMS.\u003c/p\u003e\n\n\u003cp\u003eTesting is authorized only on the targets explicitly listed as in scope. All systems and services associated with those domains, including their subdomains, are in scope unless explicitly excluded.\u003c/p\u003e\n\n\u003cp\u003eWebsites that are CMS-owned or CMS-managed and link to this policy are also considered in scope.\u003c/p\u003e\n\n\u003ch3\u003eAdditional Clarifications and Examples:\u003c/h3\u003e\n\n\u003cp\u003eVendor-operated or third-party systems are excluded from this program, even if:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThey are linked from CMS.gov or other CMS websites\u003c/li\u003e\n\u003cli\u003eAny vulnerabilities discovered in these systems should be reported directly to the vendor through their disclosure policy (if available). No bounty will be awarded for such findings.\u003c/li\u003e\n\u003cli\u003eThird-Party Platforms: Systems hosted or operated by vendors such as Salesforce, ServiceNow, or Atlassian (e.g., *.my.site.com, *.service-now.com, *.atlassian.net).\u003c/li\u003e\n\u003cli\u003eLinked Vendor Sites: Contractor-managed resources linked from CMS.gov, including FAQs, training materials, or help centers, remain out of scope.\u003c/li\u003e\n\u003cli\u003eVendor Systems Using CMS Credentials: External vendor platforms that allow login with credentials are excluded unless explicitly listed as in scope.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRedirects and Third-Party Infrastructure\u003c/h3\u003e\n\n\u003cp\u003eAny testing activity that targets, follows, or results in interaction with third-party or vendor-managed systems is out of scope.\u003c/p\u003e\n\n\u003cp\u003eThis includes, but is not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRedirects from in-scope CMS domains to external systems\u003c/li\u003e\n\u003cli\u003eProxying, API calls, or backend interactions that traverse into vendor-managed infrastructure\u003c/li\u003e\n\u003cli\u003eDirect access to vendor systems through URLs, endpoints, or infrastructure not explicitly listed as in scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eResearchers must not test, interact with, or attempt to access these systems, even if they are reachable from or initiated through an in-scope CMS domain. Findings involving such systems are not eligible for bounty.\u003c/p\u003e\n\n\u003cp\u003eThese reports should be directed to the vendor in accordance with their disclosure policy (if any).\u003c/p\u003e\n\n\u003cp\u003eAny CMS domain or asset not listed bove is out of scope. If a security researcher identifies a vulnerability in a system outside the scope, they are encouraged to report the issue through the vendor’s reporting mechanism. However, no bounty will be paid for such reports. The vendor may be able to assist with the reporting of these vulnerabilities.\u003c/p\u003e\n\n\u003cp\u003eTargets may be added or removed while the program is active, though changes are typically made during designated pause windows. These windows allow CMS and Bugcrowd to reassess scope, adjust priorities, and refine test focus areas.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eBounty Eligibility\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eThe following are not eligible for bounties:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny findings discovered outside of the Scope.  These may be reported through the CMS Vulnerability Disclosure Program \u003ca href=\"https://bugcrowd.com/engagements/cms-vdp\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eDuplicates: Vulnerabilities that share the same root cause and affect multiple sections or areas of a website will be treated as duplicates. In such cases, only the first instance of the vulnerability will be eligible for a bounty, though reporting additional instances is still encouraged to support comprehensive remediation efforts. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess/Credentials\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eUser accounts will not be provided for testing\u003c/li\u003e\n\u003cli\u003eWherever possible, researchers should include text 'Bugcrowd Bug Bounty' or 'BugcrowdCMS' in plaintext in order to deconflict logging data where true source IP may not be present\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eCredential Use \u0026amp; Authentication Restrictions:\u003c/h2\u003e\n\n\u003cp\u003eResearchers are prohibited from using leaked, breached, or exposed credentials to access CMS systems, even if discovered via open sources. Any attempt to log into systems using such credentials will be considered out of scope and a potential violation of federal policy. Submissions based on login or account takeover from third-party leaks (e.g., Telegram, data dumps) will be rejected.\u003c/p\u003e\n\n\u003ch2\u003eThird-Party \u0026amp; Leaked Data Restrictions\u003c/h2\u003e\n\n\u003cp\u003eVulnerabilities supported by data from private, invite-only, or unauthorized sources (e.g., Telegram groups, breach forums) are not accepted. Only information gathered from publicly accessible and legally obtained sources is permitted.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eScope of Findings\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eScope of Findings: Sensitive vs. Non-Sensitive Data\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eNon-Sensitive Public Documents: Documents that are publicly accessible and do not contain sensitive data, such as Personally Identifiable Information (PII), Protected Health Information (PHI), or confidential information, will not be considered valid findings. Any content labeled as “INFORMATION NOT RELEASABLE TO THE PUBLIC UNLESS AUTHORIZED BY LAW” that does not\u003cbr\u003e\npose a security or privacy risk, such as general trends, findings, or procedural information, is also not valid for reporting under this engagement. Duplicate findings on public documents will not be accepted unless new sensitive data is identified.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSensitive Data Considerations: Findings involving sensitive data, such as the following, are considered valid:\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePersonally Identifiable Information (PII): PII is any data that could individually or, when combined with other elements, identify a consumer. Examples include a consumer’s name, address, telephone number, Social Security Number, Marketplace application ID, or other identifiers. Consumers have the right to access, inspect, and/or correct their PII upon request. Assisters, such as Navigators or certified application counselors, are only permitted to create, collect, disclose, access, maintain, store, and use consumer PII for authorized purposes or with the consumer’s informed consent.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eBelow is a list of examples of PII that security researchers may encounter (this is not exhaustive):\u003c/h3\u003e\n\n\u003col\u003e\n\u003cli\u003eName\u003c/li\u003e\n\u003cli\u003eBirth date\u003c/li\u003e\n\u003cli\u003eSocial Security number\u003c/li\u003e\n\u003cli\u003eAlien Registration Number\u003c/li\u003e\n\u003cli\u003eHome address\u003c/li\u003e\n\u003cli\u003eEmail address\u003c/li\u003e\n\u003cli\u003ePhone number\u003c/li\u003e\n\u003cli\u003eElectronic or paper federal tax returns (e.g., 1040, 941, 1099, 1120, and W2)\u003c/li\u003e\n\u003cli\u003eMedicaid/CHIP eligibility status\u003c/li\u003e\n\u003cli\u003eCitizenship or immigration status\u003c/li\u003e\n\u003cli\u003eApplicant ID\u003c/li\u003e\n\u003cli\u003eHousehold income\u003c/li\u003e\n\u003cli\u003eQualified health plan (QHP) eligibility status\u003c/li\u003e\n\u003cli\u003eAdvanced payments of the premium tax credit/cost-sharing reduction (APTC/CSR) eligibility status\u003c/li\u003e\n\u003cli\u003eSpoken and written language preference\u003c/li\u003e\n\u003cli\u003eTobacco usage\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch3\u003eProtected Health Information (PHI): The Privacy Rule protects PHI that is held or transmitted in any form, including electronic, paper, or verbal. PHI includes:\u003c/h3\u003e\n\n\u003col\u003e\n\u003cli\u003e    Common identifiers, such as name, address, birth date, and Social Security Number\u003c/li\u003e\n\u003cli\u003e Information about the patient’s past, present, or future physical or mental health condition\u003c/li\u003e\n\u003cli\u003e Details on healthcare services provided to the patient\u003c/li\u003e\n\u003cli\u003e Information regarding past, present, or future payment for the healthcare provided to the patient\u003c/li\u003e\n\u003cli\u003e    Financial Information: Bank account numbers, credit card details, tax information, and financial transaction records.\u003c/li\u003e\n\u003cli\u003e    Authentication Data: Passwords, PINs, and security questions/answers used for system access.\u003c/li\u003e\n\u003cli\u003e    Government Data: Classified information and national security-related data.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eResearcher Guidelines\u003c/h2\u003e\n\n\u003cp\u003eTo be provided safe harbor as described below, researchers must read and agree to abide by the guidelines in this ROE.\u003c/p\u003e\n\n\u003ch2\u003eResearchers Must:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eImmediately cease all actions if and/or when a system is removed from scope\u003c/li\u003e\n\u003cli\u003eRespect the periods of availability and blackout dates. Any vulnerabilities discovered or reported during blackout dates or after a system has been removed from scope will not be eligible for bounties\u003c/li\u003e\n\u003cli\u003eAvoid destructive or disruptive actions to CMS information systems and operations\u003c/li\u003e\n\u003cli\u003eRefrain from exploiting any vulnerability beyond the minimal amount of testing required to prove its existence or to identify a related indicator. This means that researchers must: \u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSTOP\u003c/strong\u003e from exploiting any vulnerability if successfully able to move laterally or vertically.\n1.Provide details of exploit and await approval to proceed with escalation\u003c/li\u003e\n\u003cli\u003eAvoid intentionally accessing the data, information transiting or stored on CMS information systems, or content of any communications, except that which is directly related to a\nvulnerability and access is necessary to prove that the vulnerability exists. If a researcher encounters sensitive information, they must immediately stop and report within the confines of\nthe program\u003c/li\u003e\n\u003cli\u003eRefrain from exfiltration of data under any circumstances. This includes screenshots that may include sensitive data.\u003c/li\u003e\n\u003cli\u003eAvoid intentionally compromising anyone’s privacy or safety\u003c/li\u003e\n\u003cli\u003eAvoid intentionally compromising the intellectual property or other commercial or financial interests of any CMS personnel or entities or any legitimate third parties\u003c/li\u003e\n\u003cli\u003e Refrain from disclosing any details or information outside the terms agreed upon by CMS per the ‘Coordinated Disclosure’ provision below. Researchers must obtain explicit permission from CMS prior to disclosure of any results of a submission\u003c/li\u003e\n\u003cli\u003e Understand that any original submissions may be subject to separate disclosure by CMS under the Freedom of Information Act (FOIA)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eResearchers May:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTest in-scope CMS information systems in order to detect the vulnerability or identify an indicator related to the vulnerability for the sole purpose of providing [CMS] information about such vulnerability.\u003c/li\u003e\n\u003cli\u003eReport a product vulnerability to the affected vendor or a third-party vulnerability coordination service if a vulnerability is discovered in a CMS information system consequent to the product vulnerability or in a generally available product in order to enable the product to be fixed. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eResearchers May Not:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eUse leaked credentials to test or login to any accounts that do not belong to them\u003c/li\u003e\n\u003cli\u003eEmploy Distributed Denial of Service (DDOS)\u003c/li\u003e\n\u003cli\u003eEmploy social engineering attacks, such as phishing, attempts to compromise passwords, or any distribution of malware\u003c/li\u003e\n\u003cli\u003eAttempt lateral movements to other systems\u003c/li\u003e\n\u003cli\u003eAttempt to bypass or disable rate limiting controls, or conduct stress testing. These protections are in\nplace to ensure system stability and prevent unintentional Denial of Service (DoS).\u003c/li\u003e\n\u003cli\u003eAttempt to physically access a CMS or hosting provider facility\u003c/li\u003e\n\u003cli\u003eTest any systems or vulnerabilities not in scope\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eTypical Out of Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTheoretical vulnerabilities\u003c/li\u003e\n\u003cli\u003eInformational disclosure of non-sensitive data\u003c/li\u003e\n\u003cli\u003eLow-impact session management issues\u003c/li\u003e\n\u003cli\u003eSelf-XSS (user-defined payload)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCoordinated Disclosure\u003c/h2\u003e\n\n\u003cp\u003eIn conjunction with this ROE, the Information Security and Privacy Group commits to allowing researchers to publish mutually agreed information regarding a vulnerability after it has been remediated. CMS requires all researchers to obtain explicit permission from CMS prior to disclosing any knowledge gathered from this engagement, including vulnerabilities, indicators of vulnerabilities, data, architecture, or other system-related information. This applies to all the submissions for the program, regardless of validity or acceptance.\u003c/p\u003e\n\n\u003cp\u003eFor any vulnerability discovered through this engagement to be disclosed, all parties (CMS, the Information Security and Privacy Group, and security researcher) must agree upon the date of disclosure and the disclosure level (i.e., limited or full) and the method of disclosure. Once the vulnerability or exploit is made public by CMS, the researcher may disclose the vulnerability or exploit publicly if it adheres to the agreed level of disclosure—limited or full—and any other parameters agreed upon for the disclosure.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003eIf a researcher makes a good faith effort to comply with these ROE, CMS considers their actions to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e Authorized under the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws related to authorized access on information systems), and CMS will not recommend or pursue legal action against security researchers for accidental and good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eAuthorized and therefore CMS will not bring a claim against the researcher under the Digital Millennium Copyright Act (DMCA) for circumvention of technology controls; and\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in relevant Terms \u0026amp; Conditions that would interfere with security research conducted in accordance with this policy, and CMS  will waive those restrictions on a limited basis for work done under this policy.\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith as stated in the CMS Vulnerability Disclosure Policy (VDP)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"4c986c82-f1f3-4432-ae47-2870c5f774c1","name":"████████████████","targets":[{"id":"293c0235-3d54-4e7f-b435-3c0076c91b0a","uri":null,"name":"████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c7cf1241-d1a2-483f-8f69-8dd4fabd6a97","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"293c0235-3d54-4e7f-b435-3c0076c91b0a"},{"id":"6a6422df-c1b1-41ec-b38b-dda504c1fee1","name":"Okta","targetId":"293c0235-3d54-4e7f-b435-3c0076c91b0a"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"293c0235-3d54-4e7f-b435-3c0076c91b0a"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"293c0235-3d54-4e7f-b435-3c0076c91b0a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"293c0235-3d54-4e7f-b435-3c0076c91b0a"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"293c0235-3d54-4e7f-b435-3c0076c91b0a"}],"recentChangeFlags":null},{"id":"6ef7a0cb-4681-42ca-abed-4847049150c4","uri":null,"name":"███████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"11e86490-305c-4bc6-beb6-f372ae598590","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"6ef7a0cb-4681-42ca-abed-4847049150c4"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"6ef7a0cb-4681-42ca-abed-4847049150c4"},{"id":"6a6422df-c1b1-41ec-b38b-dda504c1fee1","name":"Okta","targetId":"6ef7a0cb-4681-42ca-abed-4847049150c4"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"6ef7a0cb-4681-42ca-abed-4847049150c4"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6ef7a0cb-4681-42ca-abed-4847049150c4"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"6ef7a0cb-4681-42ca-abed-4847049150c4"}],"recentChangeFlags":null},{"id":"02dfd757-00f1-441a-8e1c-33680f2f2de4","uri":null,"name":"███████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5954d62f-22c4-47e0-81c4-8665edad09b9","sortOrder":2},"sortOrder":2,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"},{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"},{"id":"e4ad1c44-2f86-487b-9793-0add0dbfdcf2","name":"Zone.js","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"02dfd757-00f1-441a-8e1c-33680f2f2de4"}],"recentChangeFlags":null},{"id":"293456f7-ae7c-4891-ac08-3f1b528c1924","uri":null,"name":"████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2928f8d2-47c1-4305-a185-ce71dc67c28a","sortOrder":3},"sortOrder":3,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"293456f7-ae7c-4891-ac08-3f1b528c1924"},{"id":"3a3487a7-9abf-45f0-8057-51dabed20371","name":"Drupal","targetId":"293456f7-ae7c-4891-ac08-3f1b528c1924"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"293456f7-ae7c-4891-ac08-3f1b528c1924"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"293456f7-ae7c-4891-ac08-3f1b528c1924"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"293456f7-ae7c-4891-ac08-3f1b528c1924"}],"recentChangeFlags":null},{"id":"21d37015-8f5f-43c0-9cf5-5e9e7f8f893e","uri":null,"name":"███████████████████████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d7313453-74cf-42bb-b605-5e6906f5f070","sortOrder":4},"sortOrder":4,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"21d37015-8f5f-43c0-9cf5-5e9e7f8f893e"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"21d37015-8f5f-43c0-9cf5-5e9e7f8f893e"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"21d37015-8f5f-43c0-9cf5-5e9e7f8f893e"}],"recentChangeFlags":null},{"id":"0adb1a5c-1fd7-42f6-a64a-ddc8d5686215","uri":null,"name":"████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0f2d4bad-ff9e-4d3c-bd1a-cf87a103a6dd","sortOrder":5},"sortOrder":5,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"0adb1a5c-1fd7-42f6-a64a-ddc8d5686215"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"0adb1a5c-1fd7-42f6-a64a-ddc8d5686215"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0adb1a5c-1fd7-42f6-a64a-ddc8d5686215"}],"recentChangeFlags":null},{"id":"dd01d649-7698-4437-8f87-4bf0e442a001","uri":null,"name":"█████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4a6c9954-4bae-4048-a6e1-5737a72fc5c0","sortOrder":6},"sortOrder":6,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"dd01d649-7698-4437-8f87-4bf0e442a001"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"dd01d649-7698-4437-8f87-4bf0e442a001"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"dd01d649-7698-4437-8f87-4bf0e442a001"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"dd01d649-7698-4437-8f87-4bf0e442a001"}],"recentChangeFlags":null},{"id":"bf21da36-999c-4a63-9aa5-007a55f58b1c","uri":null,"name":"███████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"046b2254-db54-4575-ad3d-c272687a14f3","sortOrder":7},"sortOrder":7,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"bf21da36-999c-4a63-9aa5-007a55f58b1c"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"bf21da36-999c-4a63-9aa5-007a55f58b1c"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"bf21da36-999c-4a63-9aa5-007a55f58b1c"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"bf21da36-999c-4a63-9aa5-007a55f58b1c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"90f738da-09c1-4ad4-83e8-9156e9067079","p1MaxCents":700000,"p1MinCents":500000,"p2MaxCents":350000,"p2MinCents":250000,"p3MaxCents":250000,"p3MinCents":100000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5000,"max":7000},"2":{"min":2500,"max":3500},"3":{"min":1000,"max":2500},"4":{"min":250,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"3c72b578-ba9e-41a0-8778-58fa6d5155de","name":"████████████████████","targets":[{"id":"2d7f13df-6de6-41bc-a9ab-3b48c9954a2b","uri":null,"name":"████████████████████████████████████████████████████████████████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0e577166-fd0d-4b2e-8d78-6836998dc418","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5145c689-43db-4c52-85d5-7b6a16570553","uri":null,"name":"██████████████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1ec9fb0f-473f-43a6-9c78-718f9e2f72e7","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"393a6116-c6d7-42e7-9de5-6e4e7e85627c","code":"cms-bbpublic","state":"in_progress_paused","endsAt":null,"bountyId":"66322b64-8bd3-488a-885a-a108bdcd9748","startsAt":"2025-12-02T16:06:36Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/675f/2da4/a0421e08/e75e6665002e007e4f12004eae1d0914_centers_for_medicare__medicaid_services_logo__2_.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Hello Hackers, \n\nWe have paused the CMS engagement for the time being. Please discontinue all testing at this time. We will send an announcement once the engagement is planned to resume. \n\nThanks!","lastTransitionAt":"2026-08-17T20:32:48.570Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/cms-bbpublic","changelogs":"/engagements/cms-bbpublic/changelog","submissions":null,"announcements":"/engagements/cms-bbpublic/announcements","hallOfFame":"/engagements/cms-bbpublic/hall_of_fames","crowdstream":"/engagements/cms-bbpublic/crowdstream"},"announcementsCount":11,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=cms-bbpublic\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/cms-bbpublic/engagement_subscribers","engagementChangelogsUrl":"/engagements/cms-bbpublic/changelog","publishedAt":"2026-08-17T20:32:48.602Z","engagementChangelogUrl":"/engagements/cms-bbpublic/changelog/ed4ad48a-148c-462f-84af-0356fb47ffd1","createUserFeedbacksUrl":"/engagements/cms-bbpublic/feedbacks","engagementCrowdstreamUrl":"/engagements/cms-bbpublic/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}