Home News Detail

CBSE Security Breach

Education News

CBSE Security Vulnerability Exposes Risks to Student Data and Marks | News


Major Security Flaws Allegedly Exposed in CBSE Digital Systems
Student records, examiner accounts, and grading systems may have been vulnerable to unauthorized access, according to cybersecurity disclosures.

Serious cybersecurity vulnerabilities discovered within the Central Board of Secondary Education’s (CBSE) digital infrastructure may have exposed sensitive student records, examiner accounts, and grading systems to unauthorized access, according to findings shared by an independent security researcher.

The vulnerabilities were reportedly identified by 19-year-old cybersecurity researcher Nisarga Adhikary in CBSE’s On-Screen Marking (OSM) portal — a platform extensively used by evaluators to assess Class 12 board examination answer sheets.

Critical Security Weaknesses Identified

Technical disclosures shared online and later amplified by cybersecurity experts suggested that the portal relied heavily on insecure client-side validation mechanisms rather than secure backend verification systems.

One of the most alarming findings involved a hardcoded master password embedded directly within publicly accessible JavaScript files. Experts warned that this flaw could potentially allow attackers to bypass the platform’s OTP-based authentication system entirely.

Researchers also identified an Insecure Direct Object Reference (IDOR) vulnerability, where examiner and validator IDs were reportedly retrieved directly from browser session storage. This could allegedly enable unauthorized users to manipulate identifiers using basic browser developer tools and gain access to examiner accounts and student evaluations.

Additional concerns were raised over the portal’s password reset mechanism, which allegedly allowed account credentials to be changed without verifying the original password.

Experts further claimed that crucial OTP validation checks were being handled on the client side rather than through secure server-side authentication, increasing the risk of unauthorized access.

Timeline of Events

February 2026: The vulnerabilities were reportedly discovered and submitted to CERT-In for responsible disclosure.

May 19, 2026: CBSE launched its post-result re-evaluation portal, following which thousands of students reported crashes and technical glitches.

May 22, 2026: Users observed unusual fluctuations in rechecking fees, with amounts reportedly ranging from Rs. 1 to Rs. 69,420 per subject.

May 26, 2026: Technical details regarding the alleged vulnerabilities went viral on social media platforms, triggering widespread public concern.

CBSE Response and Current Status

Following mounting criticism and public scrutiny, portions of the portal were temporarily taken offline for maintenance and security updates. Access to several systems has since been restricted while additional safeguards are reportedly being implemented.

In an official statement, CBSE attributed the disruptions to “unprecedented traffic” and acknowledged “attempts of unauthorized interference” on its systems. However, the board has not officially confirmed whether any student records or marks were altered before corrective measures were introduced.

The incident has reignited concerns over cybersecurity preparedness within large-scale public digital infrastructure handling sensitive educational and examination data.



Published By: Anz D
Published On: 27 May 2026
Disclaimer:
While we strive to provide accurate and reliable information, neither our platform nor any associated colleges, institutions, universities, or third-party sources shall be held liable for any errors, omissions, or discrepancies. The content is compiled from publicly available data and official sources and may be subject to change. Users are strongly advised to verify details directly through the respective official websites.

This platform serves as a centralized hub offering consolidated links, admission-related information, application forms, and updates on colleges, institutions, universities, examinations, results, schedules, notifications, and other education-related content. Our goal is to assist students and parents in navigating the online admission process, and we are committed to providing ongoing support to those who may need guidance or clarification.
Loading data, please wait...