Back to blog
Study Tips6 min read

How to Pass the HTB CWES (Formerly CBBH) in 2026: A Study Plan for the 7-Day Web Exam

HTB CWES is the renamed Certified Bug Bounty Hunter exam: seven days, a web-application target set and a commercial-grade report. Here is what Hack The Box publishes, and an 8-week plan for the 20-module path.

Tom Ashford

Tom Ashford · Security Certifications Lead

5 October 2026

If you searched for the HTB CWES and found pages about the CBBH, you are in the right place: the HTB Certified Web Exploitation Specialist (CWES) is the exam formerly known as the Certified Bug Bounty Hunter (CBBH). Hack The Box's own materials now describe it as measuring proficiency in professional bug bounty hunting and web application penetration testing.

The exam gives you seven days to attack a set of web targets and then hand in a written report. This post covers what Hack The Box officially publishes, what it does not, and an eight-week plan built around the path you must finish before you can sit it.

What the HTB CWES Exam Is

The CWES validates intermediate competence in finding security risks in web applications, API architectures and backend services. It is a hands-on practical, not a multiple-choice test.

DetailHTB CWES
Former nameHTB Certified Bug Bounty Hunter (CBBH)
Exam window7 days from starting
Prerequisite100% completion of the CWES job-role path, plus an exam voucher
DeliverableCommercial-grade penetration testing report, in English
Report formatUnencrypted PDF or ZIP, maximum 20MB
Marking timeUp to 20 business days
RetakeOne automatic second attempt if you submitted a report on the first

Hack The Box's help centre lists the points threshold for some certifications but not for the CWES, and it does not state a voucher price in the pages we checked. Candidate write-ups commonly say you need roughly eight of ten flags, but that is community reporting rather than a published figure, so confirm the current requirement on your Academy exam page before you plan around it.

Exam Tip: The report is part of the pass. Hack The Box asks for a detailed, commercial-grade report, and candidate reviews regularly name a weak report as the reason for a fail. Treat it as a deliverable, not an afterthought.

The 20-Module Path You Must Finish First

You cannot book the exam until the Web Penetration Tester job-role path shows 100% complete. It has 20 modules, graded from Fundamental to Medium difficulty:

  1. Web Requests
  2. Introduction to Web Applications
  3. Using Web Proxies
  4. Information Gathering - Web Edition
  5. Web Fuzzing
  6. JavaScript Deobfuscation
  7. Cross-Site Scripting (XSS)
  8. SQL Injection Fundamentals
  9. SQLMap Essentials
  10. Command Injections
  11. File Upload Attacks
  12. Server-side Attacks
  13. Login Brute Forcing
  14. Broken Authentication
  15. Web Attacks
  16. File Inclusion
  17. Attacking GraphQL
  18. API Attacks
  19. Attacking Common Applications
  20. Bug Bounty Hunting Process

The first six modules are groundwork. The injection, upload, inclusion and authentication modules are where most exam findings come from.

An 8-Week Study Plan

This plan assumes about ten hours a week. Compress it if you already work in application security.

Weeks 1 and 2: foundations and recon

Work through modules 1 to 6. Get fluent in an intercepting proxy, because everything later depends on it. Build a habit of writing down every request you modify and why.

Weeks 3 and 4: injection

Cover XSS, SQL injection, SQLMap, command injection and file uploads (modules 7 to 11). Do the module skills assessments without looking at your notes first. If you cannot finish one cold, repeat the module.

Weeks 5 and 6: server-side, authentication and APIs

Finish modules 12 to 18. Pay attention to chaining. The exam is described by candidates as rewarding people who combine a low-impact bug with a second step, not people who find one isolated flaw.

Week 7: the final modules and a dry run

Complete Attacking Common Applications and the Bug Bounty Hunting Process. Then write a practice report for a lab box you have already solved, using the same structure you will use in the exam: summary, finding, impact, evidence, remediation.

Week 8: rest and logistics

Test your VPN or Pwnbox setup, organise your notes by vulnerability class and sort out the days you will have free. Do not cram a new topic.

How to Spend the Seven Days

Seven days is generous for the targets and tight for the report. A sensible split:

  • Days 1 to 4: enumerate every target thoroughly and collect flags. Screenshot evidence as you go.
  • Days 5 and 6: return to anything unresolved, then stop attacking.
  • Day 7: finish the report, check every finding has reproduction steps, and submit.

Take notes in the report format from the first hour. Rebuilding evidence on day seven is how reports end up thin.

If You Fail the First Attempt

If your first attempt did not pass and you submitted a report, Hack The Box gives you one automatic second attempt. You have 14 days from receiving feedback to start it. Read the feedback closely, because it tells you which areas to fix.

Where This Fits in Your Path

The CWES is a web-application specialism. If you want broader network and Active Directory coverage, read our HTB CPTS study plan next, and see what to take after OSCP for how the lab certifications compare. If you want the source-code-review route into web security, the OffSec OSWE plan covers it.

CertCrush does not offer a course for the HTB exam itself. If you want structured pentesting fundamentals first (methodology, scoping, reporting and the attack classes above), the CompTIA PenTest+ course is the closest fit, though it prepares you for PenTest+, not the CWES.

Frequently Asked Questions

What does HTB CWES stand for?

HTB CWES stands for Hack The Box Certified Web Exploitation Specialist. It is the current name for the exam previously called the Certified Bug Bounty Hunter, or CBBH.

How long is the HTB CWES exam?

You have seven days from starting the exam to complete the practical work and submit your report. Marking can then take up to 20 business days.

Is the HTB CWES the same as the CBBH?

Candidate reviews and Hack The Box's own listings treat them as the same certification under a new name. Search results for both terms point at the same material, so a CBBH study resource is still useful if its content matches the 20-module path above.

Can I retake the HTB CWES?

If you fail the first attempt after submitting a report, Hack The Box grants one automatic second attempt. You must start it within 14 days of receiving your feedback.

Ready to Start Practising?

A web-exploitation exam rewards methodical habits more than clever tricks. Build the fundamentals first, then take them into the lab. Create a free CertCrush account to practise exam-style questions on penetration testing concepts while you work through the path.

HTB CWESHTB CBBHHack The Boxweb application securitybug bountystudy planpenetration testing
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Want a HTB CWES practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.