CBBH: HTB Certified Bug Bounty Hunter
HTB CBBH — the Certified Bug Bounty Hunter — is Hack The Box's beginner-to-intermediate web-application certification. Since October 2025 it's been renamed HTB CWES (Certified Web Exploitation Specialist); the exam is unchanged and existing holders converted automatically. You earn it through HTB Academy, where a Silver Annual subscription ($490/year) includes the voucher. The exam runs seven days and ends in a commercial-grade report. Fair, not trivial.
- Price from
- $490
- Exam
- 7-day exam
- Level
- Intermediate
- Report
- Yes
What CBBH is and who runs it
Hack The Box runs it through HTB Academy. CBBH is the web-application track: it teaches you to find and exploit common web vulnerabilities — injection, broken access control, file inclusion, SSRF and the rest — the way a bug bounty hunter or web app pentester works. It’s aimed at beginners moving toward intermediate, and it deliberately does not cover networks or Active Directory (that’s CPTS territory). One honest note up front: as of October 1, 2025, HTB renamed CBBH to CWES — Certified Web Exploitation Specialist. It’s the same exam and the same path, existing holders were auto-converted on Credly at no cost, and no re-exam is required; new candidates simply earn the CWES name.
Cost and what’s included
Same model as HTB’s other Academy certs: the exam voucher is bundled with a subscription rather than sold as a large standalone fee. The Silver Annual plan ($490/year) includes one voucher usable for CWES (formerly CBBH), among others, and unlocks the web-exploitation path you study from. The Student plan ($8/month) unlocks modules but not a certification voucher. So the realistic figure to both train and sit the exam is the $490 subscription, not a small one-off charge.
Time: the exam and the report
The exam runs seven days. You work a live web target, collect flags to prove exploitation, and — the part beginners underestimate — write a commercial-grade report documenting the vulnerabilities and remediation advice, all inside that seven-day window. There is no separate report-only day; the report is part of the exam. HTB grades afterward and returns results after review. The voucher includes a second attempt if you fall short the first time.
How hard it is, honestly
Reviewers broadly land on “not easy, but fair.” The course teaches what you need, and the exam tests whether you can chain it together on your own without hand-holding. The technical bar is intermediate; the report is what catches people off guard, because writing clearly about what you found and how to fix it is a genuine skill in its own right. If you did the path’s labs and skills assessments honestly, it’s very passable — first-timers tend to describe it as challenging but rewarding rather than brutal.
Is it worth it — and for whom
It’s a good fit if you’re getting into web app security or bug bounty and want structured proof you can actually exploit, not merely recognize, common bugs. It’s less suited to people who want breadth across networks and AD — CPTS is the better buy there — or to seasoned web pentesters who won’t learn much new. The report practice genuinely transfers to real client and program work. As always, check whether the specific role you’re chasing recognizes the HTB name, since the CBBH-to-CWES rename is still filtering through job listings.
How to prepare
Finish the required path to 100%, labs and skills assessments included — the exam mirrors that material closely. Practice writing as you go: keep clean notes, screenshots, and a report template so the write-up isn’t a scramble on day seven. Drill the core web vulnerability classes until exploitation is routine rather than something you stop to look up. Because you have a full week, pace yourself, sleep, and leave real time for the report — a solid finding with a weak write-up can still fail you.
SourcesHTB Academy certificationsHTB CBBH to CWES transition

Common questions
How much does the CBBH exam cost?
$490/yr Silver Annual (bundles the voucher). Set by Hack The Box and subject to change — confirm the current price on their page.
How long is the CBBH exam?
The CBBH exam runs 7-day exam.
Does CBBH require a written report?
Yes. Hack The Box grades a written report alongside the practical, and it counts toward whether you pass — see how the report is graded on the reports page.
Who runs the CBBH certification?
CBBH (HTB Certified Bug Bounty Hunter) is run by Hack The Box. It is an intermediate exam in the web application security track.
Can you retake the CBBH exam?
Second attempt included; 14 days from feedback to retake.
What people who sat CBBH say
The exam is therefore not easy, but it is fair.
My journey to CBBH was challenging but incredibly rewarding.