Critical Vulnerabilities in CBSE's On-Screen Marking System Exposed

Critical Vulnerabilities in CBSE's On-Screen Marking System Exposed

First seen 26 May 2026, 14:05 UTC News.YcombinatorThehindubusinesslineDevdiscourseNewsbytesappNewindianexpress+50 85% similarity 66.5

Article Content

Browse articles
ThreatCluster

Nisarga Adhikary, a 19-year-old ethical hacker, discovered severe vulnerabilities in the CBSE's On-Screen Marking (OSM) system, which is used for evaluating Class 12 board exams. The flaws include a hardcoded master password that allows full account takeover, enabling unauthorized access to alter student marks. Adhikary reported the vulnerabilities to CERT-In on February 25, 2026, but received minimal response. After months of inaction, he published his findings on May 22, 2026. CBSE has denied any security breaches, claiming the reported URL was a testing site and not operational. The incident raises significant concerns about the security of India's digital education infrastructure. The vulnerabilities could potentially affect millions of students and undermine the integrity of the examination process.

Key Points: • A hardcoded master password in the CBSE OSM system allows unauthorized access. • Nisarga Adhikary reported vulnerabilities to CERT-In but received inadequate responses. • CBSE denies any security breach, claiming the reported site was only for testing.

ThreatCluster AI

Timeline

2026-02-25
Vulnerabilities discovered by Nisarga Adhikary
Adhikary found critical flaws in the CBSE OSM system, including a hardcoded master password.
Thehindubusinessline
2026-05-22
Adhikary publishes blog detailing vulnerabilities
After receiving no substantial response from CERT-In, Adhikary goes public with his findings on his blog.
News.Ycombinator
2026-05-26
CBSE refutes claims of security breach
CBSE asserts that the vulnerabilities reported by Adhikary pertain to a non-operational testing site.
Devdiscourse
2026-05-27
News coverage of the incident continues
Media outlets report on the implications of the vulnerabilities and CBSE's denial of any breach.
Newsbytesapp

Community

Browse all →