CBSE OSM portal controversy explained in points
- A major controversy has erupted around the digital security of the Central Board of Secondary Education evaluation system.
- The issue surfaced after 19-year-old cybersecurity researcher Nisarga Adhikary claimed he discovered serious vulnerabilities in CBSE’s On-Screen Marking (OSM) portal.
- The claims gained nationwide attention after tech entrepreneur Deedy Das shared the issue publicly on X.
- Nisarga said he reported the vulnerabilities to CERT-In in February 2026.
- According to the blog post, the OSM portal is used by examiners to digitally evaluate scanned board exam answer sheets.
- Nisarga claimed the portal link was publicly accessible and several backend flaws were visible after inspecting the code.
Major vulnerabilities allegedly found
- A hardcoded “master password” was allegedly visible inside the website’s JavaScript bundle.
- According to the claims, the password could allegedly bypass the OTP authentication system.
- The researcher claimed attackers only needed an examiner’s user ID and school code to gain access.
- The OTP verification system was also allegedly flawed.
- Nisarga claimed the OTP itself was returned in the server response and validated locally on the browser.
- He alleged that anyone inspecting network requests could directly view the OTP.
- The blog claimed several internal routes like dashboard and verification pages lacked proper protection.
- According to the researcher, fake tokens and dummy user details could allegedly provide access to restricted sections.
- Another alleged flaw involved password reset functionality.
- Nisarga claimed the system allegedly allowed password changes without verifying the old password.
- He also mentioned a possible IDOR (Insecure Direct Object Reference) vulnerability.
- According to the claims, attackers could allegedly impersonate examiner accounts and take control without credentials.
Timeline of events
- Nisarga said he immediately emailed CERT-In after discovering the issues.
- He later reportedly shared screen recordings and walkthrough videos explaining the vulnerabilities.
- According to him, CERT-In acknowledged the complaint but no major follow-up updates were received.
- He alleged that several vulnerabilities remained unpatched for months.
Why the controversy is significant
- CBSE oversees more than 33,000 schools in India and abroad.
- Millions of students depend on CBSE marks for admissions, scholarships and careers.
- The controversy comes during ongoing complaints about:
- revaluation portal crashes
- blurred answer sheets
- incorrect marks
- repeated deadline extensions
- Social media users connected the issue to larger concerns around digital trust in India’s examination systems.
Public reaction online
- Many users praised Nisarga for exposing the alleged flaws.
- Others criticised institutions for weak cybersecurity practices.
- Some users urged caution because CBSE has not officially confirmed the claims.
- At the time of writing, there is no public evidence confirming whether student marks were actually altered.
Key quote from the researcher
- Nisarga wrote: “A security control that runs on the attacker’s machine isn’t a control at all.”
Current status
- Central Board of Secondary Education has not publicly confirmed the allegations.
- The authenticity and impact of the vulnerabilities are still under scrutiny.
- The controversy continues to trend online amid wider debates around exam security and digital infrastructure in India.


