CBSE portal vulnerabilities found in 20 minutes: Teen hacker Nisarga Adhikary speaks out

Share:
Audio Loading voice…
CBSE portal vulnerabilities found in 20 minutes: Teen hacker Nisarga Adhikary speaks out

Synopsis

A 19-year-old ethical hacker says he cracked the CBSE portal in 20 minutes, found a master password in public JavaScript code, and eventually uncovered access to nearly 30 million scanned answer sheets — all after the Board reportedly ignored his initial disclosure of 45 vulnerabilities for three months.

Key Takeaways

Nisarga Adhikary , 19, claims he identified CBSE portal vulnerabilities in just 20 minutes .
A master password embedded in the portal's public JavaScript code could grant access to any evaluator's account.
Adhikary says he reported 45 vulnerabilities to CBSE, which allegedly did not respond for three months .
Post-disclosure, he allegedly found access to nearly 30 million scanned answer sheets stored on an AWS bucket .
CBSE filed an FIR over a DDoS attack on its PBR portal; Adhikary denies any involvement and says he is unafraid.
Adhikary alleges the portal went live without mandatory VAPT audits , in violation of a publicly available agreement.

Nineteen-year-old ethical hacker Nisarga Adhikary has alleged serious security flaws in the CBSE portal, claiming it took him just 20 minutes to identify critical vulnerabilities — including a master password embedded in publicly accessible front-end code that could grant access to any evaluator's account. His disclosures have triggered a nationwide debate over the Board's digital infrastructure and cybersecurity practices.

How the Vulnerabilities Were Discovered

Adhikary said he began his investigation after CBSE launched its portal and issued public circulars. He located the portal link, which was open to the public, and used it as a starting point for reconnaissance. Digging into the site's front-end JavaScript — approximately 9,000 lines of code — with AI-assisted tools, he uncovered a master code password embedded within it.

'With that master password, you could access any evaluator's account as long as you had the user ID,' Adhikary said. He obtained evaluator user IDs through Google searches and other sources, and was subsequently able to log into those accounts, view evaluator papers, and generate grades.

Scale of Exposure: 30 Million Answer Sheets

Beyond the master password issue, Adhikary reportedly identified 45 vulnerabilities in total and reported them to CBSE. According to him, the Board did not respond. He waited three months — until results were declared — before going public. After disclosure, he says he discovered additional vulnerabilities that gave him access to nearly 30 million scanned answer sheets, databases, and more. He also alleged that answer sheets and question papers stored on an AWS bucket were publicly accessible online.

This comes amid ongoing scrutiny of CBSE's On-Screen Marking (OSM) system and broader questions about the Board's technology ecosystem.

On the FIR and DDoS Attack

CBSE has filed an FIR in connection with attacks on its portal, but Adhikary distanced himself and his collaborators from any wrongdoing. 'They experienced a DDoS attack on their PBR portal. None of us carried out any DDoS attack because it's a pretty pointless thing to do,' he said. When asked whether the FIR concerned him, Adhikary was unequivocal: 'No, I'm not. I'm in touch with some people connected with CBSE and some people from the cyber community. I'm not afraid at all.'

What Adhikary Says CBSE Must Fix

Adhikary argued that the root problem is institutional indifference to security reporting. 'They do not take security reports seriously and do not treat security with the importance it deserves,' he said. He pointed to a publicly available agreement that mandated COEM to conduct audits and VAPT (Vulnerability Assessment and Penetration Testing) before taking the site into production — a requirement he believes was not fulfilled.

'The site was taken into production without proper audits and security checks,' he alleged, adding that he hopes CBSE will seek more expert advice and strengthen its overall cybersecurity practices. As scrutiny of India's public digital infrastructure intensifies, Adhikary's case is likely to keep the spotlight on whether government-linked portals are meeting basic security standards.

Point of View

If accurate, points to a systemic failure rather than a one-off lapse — a government-linked board deploying a high-stakes portal without basic penetration testing, then ignoring a three-month-old vulnerability report from a teenager. The more troubling detail is not the breach itself but the alleged non-response: responsible disclosure is the cornerstone of ethical hacking, and if CBSE did not act on 45 reported issues, the question is whether any public-sector body has a functioning vulnerability intake process. The FIR over the DDoS attack, filed while the Board's own security failures remain unaddressed, risks chilling legitimate security research at precisely the moment India needs more of it.
NationPress
5 Aug 2026

Frequently Asked Questions

What vulnerabilities did Nisarga Adhikary find in the CBSE portal?
Adhikary claims he found a master password embedded in the portal's publicly accessible JavaScript code that could be used to log into any evaluator's account. He also allegedly discovered that nearly 30 million scanned answer sheets and question papers were stored on a publicly accessible AWS bucket. In total, he says he identified 45 vulnerabilities and reported them to CBSE.
Why did Adhikary wait three months before going public?
He says he reported the vulnerabilities to CBSE immediately but received no response. He waited until after the Board's results were declared — approximately three months — before publicly disclosing the flaws, in line with standard responsible disclosure practice.
Is Nisarga Adhikary worried about the FIR filed by CBSE?
No. Adhikary said he is not afraid of the FIR. He clarified that the FIR relates to a DDoS attack on CBSE's PBR portal, which he and his collaborators deny carrying out. He said he is in contact with people connected to CBSE and the cyber community.
What does Adhikary say CBSE should do to improve its cybersecurity?
He recommends that CBSE take security reports more seriously and ensure mandatory VAPT (Vulnerability Assessment and Penetration Testing) audits are conducted before any portal goes live. He alleges these audits, required under a publicly available agreement with COEM, were not performed before the portal was deployed.
What is the CBSE On-Screen Marking system and why is it under scrutiny?
The On-Screen Marking (OSM) system is CBSE's digital platform for evaluating answer sheets. It has come under scrutiny following Adhikary's allegations that the system's infrastructure — including stored answer sheets and question papers — was inadequately secured, raising concerns about the integrity and privacy of board examination data.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 2 months ago
  4. 2 months ago
  5. 2 months ago
  6. 2 months ago
  7. 2 months ago
  8. 2 months ago
Google Prefer NP
On Google