CBSE portal vulnerabilities found in 20 minutes: Teen hacker Nisarga Adhikary speaks out
Synopsis
Key Takeaways
Nineteen-year-old ethical hacker Nisarga Adhikary has alleged serious security flaws in the CBSE portal, claiming it took him just 20 minutes to identify critical vulnerabilities — including a master password embedded in publicly accessible front-end code that could grant access to any evaluator's account. His disclosures have triggered a nationwide debate over the Board's digital infrastructure and cybersecurity practices.
How the Vulnerabilities Were Discovered
Adhikary said he began his investigation after CBSE launched its portal and issued public circulars. He located the portal link, which was open to the public, and used it as a starting point for reconnaissance. Digging into the site's front-end JavaScript — approximately 9,000 lines of code — with AI-assisted tools, he uncovered a master code password embedded within it.
'With that master password, you could access any evaluator's account as long as you had the user ID,' Adhikary said. He obtained evaluator user IDs through Google searches and other sources, and was subsequently able to log into those accounts, view evaluator papers, and generate grades.
Scale of Exposure: 30 Million Answer Sheets
Beyond the master password issue, Adhikary reportedly identified 45 vulnerabilities in total and reported them to CBSE. According to him, the Board did not respond. He waited three months — until results were declared — before going public. After disclosure, he says he discovered additional vulnerabilities that gave him access to nearly 30 million scanned answer sheets, databases, and more. He also alleged that answer sheets and question papers stored on an AWS bucket were publicly accessible online.
This comes amid ongoing scrutiny of CBSE's On-Screen Marking (OSM) system and broader questions about the Board's technology ecosystem.
On the FIR and DDoS Attack
CBSE has filed an FIR in connection with attacks on its portal, but Adhikary distanced himself and his collaborators from any wrongdoing. 'They experienced a DDoS attack on their PBR portal. None of us carried out any DDoS attack because it's a pretty pointless thing to do,' he said. When asked whether the FIR concerned him, Adhikary was unequivocal: 'No, I'm not. I'm in touch with some people connected with CBSE and some people from the cyber community. I'm not afraid at all.'
What Adhikary Says CBSE Must Fix
Adhikary argued that the root problem is institutional indifference to security reporting. 'They do not take security reports seriously and do not treat security with the importance it deserves,' he said. He pointed to a publicly available agreement that mandated COEM to conduct audits and VAPT (Vulnerability Assessment and Penetration Testing) before taking the site into production — a requirement he believes was not fulfilled.
'The site was taken into production without proper audits and security checks,' he alleged, adding that he hopes CBSE will seek more expert advice and strengthen its overall cybersecurity practices. As scrutiny of India's public digital infrastructure intensifies, Adhikary's case is likely to keep the spotlight on whether government-linked portals are meeting basic security standards.