CyberAar

Programs / CyberAar

CyberAar

Open Public

CyberAar's official program, the company behind AarMe. Test the platform itself, its API and the main cyberaar.io website.

Bounty: 30,000 - 500,000 FCFA Open since: 2026-07-24
Submit a report

Scope

Assets in scope

Asset URL Criticality
AarMe Platform aarhack.cyberaar.io Critical
Form API cyberaar.io/api/* Sensitive
Main website cyberaar.io Standard

Rewards

Bounty table

Amount determined by CVSS severity x asset criticality. Payment via Wave or Orange Money after KYC validation.

Severity (CVSS) Critical Sensitive Standard
Critical 9.0 - 10.0 500,000 FCFA 300,000 FCFA 150,000 FCFA
High 7.0 - 8.9 300,000 FCFA 150,000 FCFA 75,000 FCFA
Medium 4.0 - 6.9 150,000 FCFA 75,000 FCFA 30,000 FCFA
Low 0.1 - 3.9 Hall of Fame Hall of Fame Hall of Fame

Rules

Engagement rules

In scope

  • Injection (SQLi, XSS, XXE, SSTI...)
  • Authentication and session management
  • Access control and IDOR
  • Sensitive data exposure
  • Malicious file upload
  • SSRF and RCE

Out of scope

  • DoS / DDoS attacks
  • Social engineering
  • Modifying or deleting real data
  • Disclosure before confirmed fix
  • Automated scanning without PoC
  • Clickjacking without demonstrated impact

SLA

Response commitments

24 business hours

Automated acknowledgement upon submission.

5 business days

Initial triage and severity assignment.

30 days

Target remediation for Critical and High findings.

90 days

Target remediation for Medium and Low. Coordinated disclosure possible after this deadline.

The program is open. Submit your report directly.

Submit a report Platform rules