Critical Vulnerabilities in CBSE's On-Screen Marking System Exposed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Nisarga Adhikary, a 19-year-old ethical hacker, discovered severe vulnerabilities in the CBSE's On-Screen Marking (OSM) system, which is used for evaluating Class 12 board exams. The flaws include a hardcoded master password that allows full account takeover, enabling unauthorized access to alter student marks. Adhikary reported the vulnerabilities to CERT-In on February 25, 2026, but received minimal response. After months of inaction, he published his findings on May 22, 2026. CBSE has denied any security breaches, claiming the reported URL was a testing site and not operational. The incident raises significant concerns about the security of India's digital education infrastructure. The vulnerabilities could potentially affect millions of students and undermine the integrity of the examination process.
Key Points: • A hardcoded master password in the CBSE OSM system allows unauthorized access. • Nisarga Adhikary reported vulnerabilities to CERT-In but received inadequate responses. • CBSE denies any security breach, claiming the reported site was only for testing.