CBBH
HackTheBox

HTB Certified Bug Bounty Hunter

Intermediate Multi-day practical web bug-bounty style exam + report Pass: Report/objective quality based; exact threshold n… $210

CBBH is a practical bug-bounty oriented credential centered on modern web/API attack techniques and reproducible findings. For 2026, focus on authz logic, chaining medium-severity issues, and crisp PoCs.

Official Page
IssuerHackTheBox
FormatMulti-day practical web bug-bounty style exam + report
DurationUp to 7 days (indicative)
Pass ScoreReport/objective quality based; exact threshold n…
Cheat Sheets
Exam-Day Workflow (2026)
- Build a strict recon -> validate -> exploit -> prove impact -> report loop. - Record every command/output pair with timestamps. - Keep fallback paths for each objective. - Use indicative timelines: first pass discovery, second pass depth, final pass report polish. - Validate findings twice before documenting business impact.
Reporting Checklist
- Executive risk summary per objective/domain - Technical evidence (request/response, command output, screenshots) - Reproduction steps with minimal ambiguity - Clear remediation with priority and owner suggestions - Retest guidance and residual risk notes