Feed
Bounty Rolling

Live Nation bug bounty on HackerOne: up to $10,000

Live Nation pays up to $10,000 for security bugs in its Ticketmaster sites and apps. The HackerOne program opened on 24 September 2026.

Live Nation runs a public bug bounty on HackerOne. The program launched on 24 September 2026 and is open to new reports. It pays for security bugs in listed Live Nation and Ticketmaster websites and in the Ticketmaster apps on iOS and Android.

The bounty table has three rows. Two rows pay $400, $1,000, $4,000 and $10,000 from the lowest listed severity up to critical. One row pays $200, $500, $2,000 and $5,000. The highest critical reward is $10,000. The lowest amount on the table is $200. Rewards follow severity and the impact the report shows. Duplicate reports and bugs outside the listed assets are not paid.

In scope are issues such as account takeover, broken access control, injection, and unauthorized access to personal or payment data on the listed assets. Cross site scripting, denial of service, social engineering and physical testing are out of scope. Assets that are not listed are out of scope. A report must not name specific artists, events or teams.

A valid report needs clear steps to reproduce the bug and proof of impact. Live Nation accepts only bugs found by a person. One bug goes in each report. Testing uses only the researcher's own accounts. Public disclosure is not allowed, including after a fix. Reports go through the Live Nation program page on HackerOne.

Source · hackerone.com/live_nation Published 24 September 2026 · Added here 27 September 2026