19-year-old cyber researcher Nisarga Adhikary alleges vulnerabilities in CBSE evaluation system

CBSE OSM portal controversy explained in points

  • A major controversy has erupted around the digital security of the Central Board of Secondary Education evaluation system.
  • The issue surfaced after 19-year-old cybersecurity researcher Nisarga Adhikary claimed he discovered serious vulnerabilities in CBSE’s On-Screen Marking (OSM) portal.
  • The claims gained nationwide attention after tech entrepreneur Deedy Das shared the issue publicly on X.
  • Nisarga said he reported the vulnerabilities to CERT-In in February 2026.
  • According to the blog post, the OSM portal is used by examiners to digitally evaluate scanned board exam answer sheets.
  • Nisarga claimed the portal link was publicly accessible and several backend flaws were visible after inspecting the code.

Major vulnerabilities allegedly found

  • A hardcoded “master password” was allegedly visible inside the website’s JavaScript bundle.
  • According to the claims, the password could allegedly bypass the OTP authentication system.
  • The researcher claimed attackers only needed an examiner’s user ID and school code to gain access.
  • The OTP verification system was also allegedly flawed.
  • Nisarga claimed the OTP itself was returned in the server response and validated locally on the browser.
  • He alleged that anyone inspecting network requests could directly view the OTP.
  • The blog claimed several internal routes like dashboard and verification pages lacked proper protection.
  • According to the researcher, fake tokens and dummy user details could allegedly provide access to restricted sections.
  • Another alleged flaw involved password reset functionality.
  • Nisarga claimed the system allegedly allowed password changes without verifying the old password.
  • He also mentioned a possible IDOR (Insecure Direct Object Reference) vulnerability.
  • According to the claims, attackers could allegedly impersonate examiner accounts and take control without credentials.

Timeline of events

  • Nisarga said he immediately emailed CERT-In after discovering the issues.
  • He later reportedly shared screen recordings and walkthrough videos explaining the vulnerabilities.
  • According to him, CERT-In acknowledged the complaint but no major follow-up updates were received.
  • He alleged that several vulnerabilities remained unpatched for months.

Why the controversy is significant

  • CBSE oversees more than 33,000 schools in India and abroad.
  • Millions of students depend on CBSE marks for admissions, scholarships and careers.
  • The controversy comes during ongoing complaints about:
    • revaluation portal crashes
    • blurred answer sheets
    • incorrect marks
    • repeated deadline extensions
  • Social media users connected the issue to larger concerns around digital trust in India’s examination systems.

Public reaction online

  • Many users praised Nisarga for exposing the alleged flaws.
  • Others criticised institutions for weak cybersecurity practices.
  • Some users urged caution because CBSE has not officially confirmed the claims.
  • At the time of writing, there is no public evidence confirming whether student marks were actually altered.

Key quote from the researcher

  • Nisarga wrote: “A security control that runs on the attacker’s machine isn’t a control at all.”

Current status

  • Central Board of Secondary Education has not publicly confirmed the allegations.
  • The authenticity and impact of the vulnerabilities are still under scrutiny.
  • The controversy continues to trend online amid wider debates around exam security and digital infrastructure in India.
nisarga reported to cbse
blog 1
Share This Article