{"id":14962,"date":"2026-05-31T14:12:25","date_gmt":"2026-05-31T08:42:25","guid":{"rendered":"https:\/\/banitoday.com\/anyone-can-download-teen-hacker-alleges-cbse-answer-sheets-were-exposed-online\/"},"modified":"2026-05-31T14:12:25","modified_gmt":"2026-05-31T08:42:25","slug":"anyone-can-download-teen-hacker-alleges-cbse-answer-sheets-were-exposed-online","status":"publish","type":"post","link":"https:\/\/banitoday.com\/hi\/anyone-can-download-teen-hacker-alleges-cbse-answer-sheets-were-exposed-online\/","title":{"rendered":"&#8216;Anyone can download&#8217;: Teen hacker alleges CBSE answer sheets were exposed online"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-131420255,imgsize-36612,width-400,height-225,resizemode-4\/screenshot-2026-05-31-131016.jpg\" alt=\"'Anyone can download': Teen hacker alleges CBSE answer sheets were exposed online\" title=\".\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p>Days after alleging security flaws in CBSE\u2019s digital evaluation system, 19-year-old ethical hacker Nisarga Adhikary has claimed that scanned answer sheets and question papers linked to the board were publicly accessible.<span class=\"id-r-component br\" data-pos=\"2\"\/>In a post on X, Adhikary alleged that an AWS bucket containing 2026 answer sheets and question papers could be accessed without authentication. \u201cCBSE people didn&#8217;t configure their AWS bucket properly and now we can paginate &amp; enumerate all their media which has 2026 answersheets &amp; question papers. ListObjectsV2 works without any auth and the bucket root is listable too \u2014 anyone on the internet can download any scanned booklet \u2014 across institutions.<!-- --> Multiple institutions are using the same bucket, insanely insecure,\u201d he wrote.<span class=\"id-r-component br\" data-pos=\"7\"\/>According to Adhikary, the issue stemmed from a cloud storage configuration that allowed users to browse and download files without logging in or providing credentials. He also claimed that multiple institutions were using the same storage bucket, increasing the scale of the alleged exposure.<span class=\"id-r-component br\" data-pos=\"9\"\/>Screenshots shared by Adhikary appeared to show scanned answer booklets arranged in a file directory.<span class=\"id-r-component br\" data-pos=\"12\"\/><span class=\"id-r-component br\" data-pos=\"14\"\/>Congress leader Jairam Ramesh shared Adhikary\u2019s post on X writing, \u201cIn today\u2019s developments on Mantri Pradhan\u2019s Ministry of Scandals, the answer sheets of 2 million CBSE Grade 12 students have been shown to be available in the public domain. This is a data breach of monumental proportions and it compromises the privacy of 2 million students,\u201d Ramesh wrote.<span class=\"id-r-component br\" data-pos=\"16\"\/>The allegations come shortly after Adhikary claimed to have found several vulnerabilities in CBSE\u2019s On-Screen Marking (OSM) portal. <!-- -->In a blog post titled \u201cExposing Critical Vulnerabilities in CBSE\u2019s On-Screen Marking Portal\u201d, he said he discovered the issues on February 25 and reported them to CERT-In before making them public.<span class=\"id-r-component br\" data-pos=\"20\"\/>\u201cI was able to log in as an examiner and reach the evaluation dashboard, where I could view and edit marks,\u201d Adhikary wrote in the blog. He also alleged that OTP verification could be bypassed and that several reported issues remained unpatched for an extended period.<span class=\"id-r-component br\" data-pos=\"23\"\/>As the claims gained traction, users reported that the OSM portal had become temporarily inaccessible. CBSE later responded to the allegations, stating that the URL cited in social media posts was not the portal used for actual evaluation work.<span class=\"id-r-component br\" data-pos=\"25\"\/>\u201cAt the outset, it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post,\u201d CBSE said in a statement posted on X.<span class=\"id-r-component br\" data-pos=\"28\"\/>The board further stated that the website identified by Adhikary was only a testing platform containing sample data. \u201cThere are no actual evaluation data, marks or other data held on that portal. The Board emphasises that no security breaches have come to light on the Portal deployed for the actual evaluation work,\u201d the statement added.<span class=\"id-r-component br\" data-pos=\"30\"\/><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/education\/news\/anyone-can-download-teen-hacker-alleges-cbse-answer-sheets-were-exposed-online\/articleshow\/131420123.cms\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Days after alleging security flaws in CBSE\u2019s digital evaluation system, 19-year-old ethical hacker Nisarga Adhikary has claimed that scanned answer sheets and question papers linked to the board were publicly accessible.In a post on X, Adhikary alleged that an AWS bucket containing 2026 answer sheets and question papers could be accessed without authentication. \u201cCBSE people [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":14963,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[264],"tags":[],"class_list":["post-14962","post","type-post","status-publish","format-standard","has-post-thumbnail","category-education"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/14962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/comments?post=14962"}],"version-history":[{"count":0,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/14962\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media\/14963"}],"wp:attachment":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media?parent=14962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/categories?post=14962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/tags?post=14962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}