How severity and rewards are decided

CVSS v3.1 sets the starting score, business impact adjusts it, and the program pays from its own band. How that works in practice.

Last updated 18 Sep 2026 · 18 days ago

Severity drives the payout, so it is the number people argue about most. Sentinel uses two steps: a CVSS v3.1 base score, then an adjustment for business impact.

CVSS v3.1 is the starting point

Triagers score the base metrics only: attack vector, complexity, privileges required, user interaction, scope, and the three impact metrics. Temporal and environmental metrics are not used, because they change over time and would make old reports unscorable.

Two rules keep scores honest:

  • Score what you demonstrated, not what you believe is possible. An SQL injection proven with a boolean oracle is scored for confidentiality impact, not as code execution you did not show.
  • PR:N means genuinely unauthenticated. A bug reachable only after free-tier signup is PR:L, though the adjustment may push it back up when signup is unverified.

Business impact is the adjustment

The base score treats every system as equivalent. It is not. The adjustment asks what the asset holds and who depends on it. A stored XSS in an admin console that can issue refunds outranks the same bug in a marketing microsite, though CVSS scores them identically.

Up a band: the asset holds payment data, health records or private messages; the bug crosses a tenant boundary; exploitation leaves nothing in the audit log.

Down a band: the asset is a demo tenant with synthetic data; a compensating control blocks the realistic path and the triager can name it; exploitation needs an improbable victim action.

Bands and typical rewards

These are platform defaults. Every program sets its own table, and the numbers on its page in the directory govern.

Band CVSS v3.1 Typical impact Typical reward
Critical 9.0 to 10.0 Remote code execution, zero-interaction account takeover, cross-tenant data access 3,000 to 25,000 USD
High 7.0 to 8.9 Auth bypass with a precondition, stored XSS in an authenticated app, SSRF into internal services 1,000 to 5,000 USD
Medium 4.0 to 6.9 IDOR on non-sensitive records, reflected XSS, CSRF on a state-changing action 250 to 1,000 USD
Low 0.1 to 3.9 Limited information disclosure, open redirect, rate-limit gaps with a shown consequence 50 to 250 USD

Duplicates

The first valid report wins. "First" is the server-received UTC timestamp on your report, shown in its timeline. Later reports of the same root cause close as Duplicate and are not paid.

Duplicate is judged by root cause, not by URL, so three parameters feeding one unsanitized helper are one bug. A duplicate of an Informative report is not a duplicate: if the original closed without a fix and yours shows real impact, ask for a re-review.

Chained vulnerabilities

A chain is filed as one report, scored on the outcome of the whole chain, and paid once at that band. Do not split a chain to collect several bounties. If a link is independently exploitable and valuable, file it separately and cross-reference both. A chain that includes an already-accepted low-severity issue still counts: the low finding is not paid twice, but it raises the chain's band.

Bonus multipliers

Programs may apply a multiplier on top of the band, set per program and shown on its page:

  • Exceptional report, 1.1x to 1.25x: minutes to reproduce, complete evidence, usable fix suggestion.
  • Priority target, 1.5x to 2x: the asset is on the program's current focus list.
  • First blood, flat bonus: first valid finding on a newly launched asset.
  • Working patch, flat bonus: you supply a fix the program ships.

Multipliers apply to the base bounty, never to each other, and never retroactively.

What "Informative" means

Informative is a real observation with no actionable risk under the program's model: a missing header with no demonstrated attack, a version banner, a finding on an asset the program has decided not to defend. It does not pay, and it does not block anyone else's report.

Severity is a judgment call

The adjustment is a human decision, and humans disagree. Treat a band as an argued position, not arithmetic. If you think it is wrong, use the appeal path:

  1. Reply in the thread within 14 days of the severity being set. State the band you expect and the impact the triager missed. New evidence beats a re-argued vector.
  2. Program re-review, answered within 7 business days.
  3. Sentinel mediation. If the program declines or goes silent, use "Request mediation". A mediator reads both sides and posts a non-binding recommendation within 10 business days.

Mediation does not change disclosure timing; see the disclosure policy. For presenting impact so the band is right the first time, see report quality.