Report a vulnerability
If you believe you have found a security vulnerability in an Acconeer product, firmware, or SDK, we want to hear from you. Please send your report to:
We follow a coordinated disclosure policy – you can find the full details in our Coordinated Vulnerability Disclosure Policy.
What to include in your report
To help us triage your report quickly, please include:
- The affected product, firmware version, or software component
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any supporting material such as proof-of-concept code or screenshots
- Your contact details and preferred communication method
If you would like to encrypt your report, please request our PGP public key at security@acconeer.com before sending sensitive details.
Please do not report security vulnerabilities through public GitHub issues, forum posts, or social media. Doing so may expose other users to risk before a fix is available.
What happens after you report
| Timeframe | What we do |
|---|---|
| Within 5 business days | Acknowledge receipt of your report |
| Within 14 days | Provide an initial assessment — whether the issue is valid, which products are affected, and our severity rating |
| Within 90 days | Aim to have a fix available or a mitigation in place, and keep you informed of progress |
| At resolution | Notify you when the fix is released and coordinate public disclosure with you |
We will not ask you to keep the vulnerability confidential beyond 90 days from your initial report, unless we agree an extension together.
Our commitments to you
When you report in good faith and follow our policy, we commit to:
- Not pursuing legal action against you for responsible discovery and reporting
- Keeping your identity confidential – we will not share it with third parties without your permission
- Crediting you in our security advisory if you wish
- Working cooperatively and keeping you informed throughout
We do not operate a bug bounty programme.
Products covered
This page covers security issues in:
- Acconeer radar sensor modules and ICs: A111, A121, A212, XM122, XM123, XM124, XM125, XM126, XM131, XM132
- Firmware, bootloaders, and software shipped as part of those products
- Acconeer SDK components and libraries included in product deliveries
- acconeer.com and developer.acconeer.com
Development hardware (XA, XB, XC, XE, XV series) and third-party products are out of scope.
Regulatory context
Acconeer AB complies with Regulation (EU) 2024/2847 (Cyber Resilience Act). Where a reported vulnerability constitutes an actively exploited vulnerability or a severe incident, we are required to notify ENISA and CERT-SE (Sweden’s national CSIRT) within statutory timelines. We will inform you if your report triggers these obligations.
Security contact: security@acconeer.com Policy version: 1.0 — September 2026 Acconeer AB, Västra Varvsgatan 19, 211 77 Malmö, Sweden
