What CNA status means

A direct, accountable path into the CVE ecosystem.

As a CVE Numbering Authority, Hackrate can assign CVE IDs and publish corresponding CVE Records for eligible vulnerabilities within its approved scope.

CVE ID Assignment

Reserve and assign a unique CVE ID when the vulnerability meets CVE Program requirements, falls within Hackrate’s scope, and is not already covered by an existing record.

CVE Record Preparation

Structure the public record with a clear vulnerability description, affected products and versions, references, credits, and additional technical data where appropriate.

Coordinated Publication

Align the CVE Record with vendor approval, remediation progress, the public advisory, and the agreed disclosure timeline.

The coordination process

A controlled process from report to public record.

01Start the Request

Hackrate customers can initiate the process from an eligible report in Resolved status. External companies and researchers can submit an initial request with the affected vendor, product, report status, and disclosure context.

02Confirm Scope and Eligibility

Hackrate assesses whether the issue represents a CVE-eligible vulnerability, whether Hackrate is the appropriate CNA, and whether an existing or reserved CVE ID may already cover the same issue.

03Validate and Prepare

Our team reviews the technical evidence and prepares the proposed CVE Record data, including affected products and versions, the vulnerability description, references, credits, remediation status, and optional enrichment such as CWE or CVSS information where appropriate.

04Review and Coordinate Disclosure

The affected company or program owner reviews the proposed public wording and agrees the disclosure timeline. A CVE ID may be reserved during this coordination phase, while sensitive details remain private until the agreed publication point.

05Publish and Maintain

Once the vulnerability is disclosure-ready and the public content has been approved, Hackrate coordinates publication of the CVE Record and the related public advisory. If relevant facts change later, the CVE Record can be updated in accordance with CVE Program rules.

Who we support

CVE support for customers, companies, and security researchers.

The path differs by audience, but the objective is the same: an eligible, validated, non-duplicate vulnerability record published through a responsible and coordinated disclosure process.

Hackrate Customers

Hackrate customers have the most integrated route to CVE coordination.

For an eligible report in Resolved status, an authorized customer user can request CVE support directly from the report. The platform generates a first draft from the validated report data, which is then reviewed by Hackrate. The customer reviews and approves the public wording and disclosure timing. Once approved, Hackrate coordinates the public Hacktivity advisory and the corresponding CVE Record using only the information authorized for disclosure.

Nothing is published automatically, and requesting CVE support does not guarantee that the report will be eligible for a CVE ID.
Explore the Customer Workflow

Companies Outside the Hackrate Platform

You do not need to operate an existing Hackrate program to ask for CVE coordination support. We can assess whether a vulnerability may fall within Hackrate’s CNA scope, review the available technical evidence, support record preparation, and coordinate the process through a structured Hackrate workflow.

If another CNA has clear authority for the affected product, Hackrate will help identify the appropriate route rather than create a duplicate or conflicting assignment.
Discuss an External CVE Request

Security Researchers and Pentesters

We welcome requests from security researchers and penetration testers who have discovered a vulnerability and want to pursue responsible CVE publication.

To evaluate the request, we need a reproducible technical report, clear affected product and version information, evidence that the affected vendor has been contacted, and an agreed path toward remediation and public disclosure. A public advisory does not need to exist before CVE coordination begins, but an appropriate public reference must be ready when the CVE Record is published.

Hackrate normally requires the affected company or program owner to approve the public disclosure plan before publication.
Request Researcher Support

CVE support and the Cyber Resilience Act

Connect coordinated vulnerability disclosure with optional CVE support.

The Cyber Resilience Act requires manufacturers of products with digital elements to put in place and enforce a coordinated vulnerability disclosure policy and to maintain processes for handling vulnerabilities reported from internal and external sources.

Hackrate managed VDP provides a structured reporting channel, technical validation, researcher communication, traceability, and optional CVE coordination when a public identifier is appropriate.

Clarification: A CVE is not required for every vulnerability, and CVE support alone does not establish CRA compliance. It can, however, support a consistent public identification and disclosure process for eligible product vulnerabilities when the manufacturer decides that a CVE Record is appropriate.
Explore Hackrate Managed VDP

FAQ

CVE coordination, clearly explained.

Straight answers about eligibility, timing, scope, and responsible publication.

A CVE ID is a unique identifier assigned to a publicly disclosed cybersecurity vulnerability. It helps vendors, researchers, security teams, tools, and vulnerability databases refer to the same issue consistently.

A CVE Numbering Authority, or CNA, is an organization authorized by the CVE Program to assign CVE IDs and publish corresponding CVE Records within a defined scope.

No, Hackrate can assign CVE IDs only when the vulnerability is eligible, falls within Hackrate’s approved CNA scope, is not a duplicate, and is not more appropriately handled by another CNA.

CVE coordination should normally begin before public disclosure.

A CVE ID may be reserved during the coordination process. However, an appropriate public advisory or reference must be prepared for publication with the CVE Record.

No. Hackrate customers benefit from the most integrated workflow, but companies and security researchers outside the platform may also request support.

Yes. Researchers and penetration testers may request support for vulnerabilities they have discovered.

Hackrate will normally require a reproducible technical report, affected product and version information, evidence of vendor engagement, and an agreed public disclosure path.

No. CVE creation is optional and must be explicitly requested. The vulnerability must also pass Hackrate’s scope, eligibility, validation, duplication, and disclosure checks.

No. New vulnerabilities should be submitted through the relevant Hackrate program, vulnerability disclosure channel, or secure reporting process.

The timeline depends on technical validation, vendor responsiveness, remediation progress, CNA scope, duplication checks, and the agreed public disclosure date. Hackrate does not publish a CVE Record before the required coordination and approval steps are complete.

Need a clear path to CVE publication?

Whether you manage vulnerability reports in Hackrate, represent an affected company, or discovered the vulnerability as a security researcher, our team can help assess the appropriate next step. We review scope and eligibility before any public disclosure takes place.

Request CVE Support
Hackrate

Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.

US Patent Applied for HackGATE #63/645,845

Checking service status...

Hackrate Ethical Hacking Platform |
2026 ©

CVE Numbering Authority