Report a vulnerability

If you believe you have found a security vulnerability in an Acconeer product, firmware, or SDK, we want to hear from you. Please send your report to:

security@acconeer.com

We follow a coordinated disclosure policy – you can find the full details in our Coordinated Vulnerability Disclosure Policy.


What to include in your report

To help us triage your report quickly, please include:

  • The affected product, firmware version, or software component
  • A description of the vulnerability and its potential impact
  • Step-by-step instructions to reproduce the issue
  • Any supporting material such as proof-of-concept code or screenshots
  • Your contact details and preferred communication method

If you would like to encrypt your report, please request our PGP public key at security@acconeer.com before sending sensitive details.

Please do not report security vulnerabilities through public GitHub issues, forum posts, or social media. Doing so may expose other users to risk before a fix is available.


What happens after you report

TimeframeWhat we do
Within 5 business daysAcknowledge receipt of your report
Within 14 daysProvide an initial assessment — whether the issue is valid, which products are affected, and our severity rating
Within 90 daysAim to have a fix available or a mitigation in place, and keep you informed of progress
At resolutionNotify you when the fix is released and coordinate public disclosure with you

We will not ask you to keep the vulnerability confidential beyond 90 days from your initial report, unless we agree an extension together.


Our commitments to you

When you report in good faith and follow our policy, we commit to:

  • Not pursuing legal action against you for responsible discovery and reporting
  • Keeping your identity confidential – we will not share it with third parties without your permission
  • Crediting you in our security advisory if you wish
  • Working cooperatively and keeping you informed throughout

We do not operate a bug bounty programme.


Products covered

This page covers security issues in:

  • Acconeer radar sensor modules and ICs: A111, A121, A212, XM122, XM123, XM124, XM125, XM126, XM131, XM132
  • Firmware, bootloaders, and software shipped as part of those products
  • Acconeer SDK components and libraries included in product deliveries
  • acconeer.com and developer.acconeer.com

Development hardware (XA, XB, XC, XE, XV series) and third-party products are out of scope.


Regulatory context

Acconeer AB complies with Regulation (EU) 2024/2847 (Cyber Resilience Act). Where a reported vulnerability constitutes an actively exploited vulnerability or a severe incident, we are required to notify ENISA and CERT-SE (Sweden’s national CSIRT) within statutory timelines. We will inform you if your report triggers these obligations.


Security contact: security@acconeer.com Policy version: 1.0 — September 2026 Acconeer AB, Västra Varvsgatan 19, 211 77 Malmö, Sweden