{"id":15182,"date":"2026-06-01T02:42:17","date_gmt":"2026-05-31T21:12:17","guid":{"rendered":"https:\/\/banitoday.com\/cbse-vs-student-board-admits-flaws-after-teen-hacker-exposes-website-vulnerabilities\/"},"modified":"2026-06-01T02:42:17","modified_gmt":"2026-05-31T21:12:17","slug":"cbse-vs-student-board-admits-flaws-after-teen-hacker-exposes-website-vulnerabilities","status":"publish","type":"post","link":"https:\/\/banitoday.com\/hi\/cbse-vs-student-board-admits-flaws-after-teen-hacker-exposes-website-vulnerabilities\/","title":{"rendered":"CBSE vs student: Board admits flaws after teen hacker exposes website vulnerabilities"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"e9jwa\">\n<div class=\"vdo_embedd\">\n<div class=\"GfdvZ\">\n<section class=\"_bIDB  clearfix id-r-component leadmedia undefined undefined  E9tg9 \" style=\"top:0px\">\n<div class=\"_bIDB\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">\n<div class=\"ypVvZ\">\n<div class=\"WGttI\"><img src=\"https:\/\/static.toiimg.com\/thumb\/msid-131420729,imgsize-30878,width-400,height-225,resizemode-4\/2026-05-31-140209.jpg\" alt=\"CBSE vs student: Board admits flaws after teen hacker exposes website vulnerabilities\" title=\".\" decoding=\"async\" fetchpriority=\"high\"\/><\/div>\n<\/div>\n<\/div>\n<\/section>\n<\/div><\/div>\n<\/div>\n<p><span class=\"id-r-component br\" data-pos=\"0\"\/>The Central Board of Secondary Education (CBSE) on Sunday said it has contained vulnerabilities identified in the OnMark portal of its service provider and is working with cybersecurity experts to further strengthen the system.<span class=\"id-r-component br\" data-pos=\"3\"\/>The board also thanked ethical hackers and members of the public who brought the issues to its notice. \u201cWe are grateful to all alert citizens and ethical hackers pointing out such weaknesses, and have gotten in touch with some of them directly,\u201d the statement said.<span class=\"id-r-component br\" data-pos=\"5\"\/>The statement comes after 19-year-old ethical hacker Nisarga Adhikary alleged security flaws in CBSE&#8217;s digital evaluation ecosystem. In a blog post, Adhikary claimed he had identified multiple vulnerabilities in the On-Screen Marking (OSM) portal that could potentially allow unauthorised access to examiner accounts and evaluation functions.<span class=\"id-r-component br\" data-pos=\"9\"\/>The board said it had been closely monitoring the issues that were recently flagged in the public domain.<span class=\"id-r-component br\" data-pos=\"11\"\/><span class=\"strong\" data-ua-type=\"1\" onclick=\"stpPgtnAndPrvntDefault(event)\">Also read:<\/span><a href=\"https:\/\/timesofindia.indiatimes.com\/education\/news\/anyone-can-download-teen-hacker-alleges-cbse-answer-sheets-were-exposed-online\/articleshow\/131420123.cms\" rel=\"noopener\" styleobj=\"[object Object]\" class=\"strong\" commonstate=\"[object Object]\" frmappuse=\"1\"> Teen hacker alleges CBSE answer sheets were exposed online<\/a><span class=\"id-r-component br\" data-pos=\"14\"\/>\u201cWe have been closely monitoring the vulnerabilities in the OnMark portal of our service provider that are being flagged in the public domain,\u201d CBSE said.<span class=\"id-r-component br\" data-pos=\"16\"\/> <span class=\"id-r-component br\" data-pos=\"19\"\/>According to the board, a team of cybersecurity experts drawn from different government agencies and Indian Institutes of Technology (IITs) has been deployed over the past few days to secure the platform and move it to a more robust setup.<span class=\"id-r-component br\" data-pos=\"22\"\/><span class=\"id-r-component br\" data-pos=\"24\"\/>\u201cAn expert team of cybersecurity professionals has been deployed over the last few days from across various arms of the government as well as the IITs to fortify these systems, including taking them over to a more secure set up,\u201d the board said..<span class=\"id-r-component br\" data-pos=\"26\"\/>Earlier, CBSE had rejected claims that its actual evaluation platform had been compromised. The board said the URL highlighted in social media posts was only a testing portal containing sample data and not the system used for live evaluation work.<span class=\"id-r-component br\" data-pos=\"29\"\/>In a post on Sunday, Adhikary alleged that an AWS bucket containing 2026 answer sheets and question papers could be accessed without authentication. \u201cCBSE people didn&#8217;t configure their AWS bucket properly and now we can paginate &amp; enumerate all their media which has 2026 answersheets &amp; question papers. ListObjectsV2 works without any auth and the bucket root is listable too \u2014 anyone on the internet can download any scanned booklet \u2014 across institutions.<!-- --> Multiple institutions are using the same bucket, insanely insecure,\u201d he wrote.<span class=\"id-r-component br\" data-pos=\"33\"\/>Screenshots shared by Adhikary appeared to show scanned answer booklets arranged in a file directory.<span class=\"id-r-component br\" data-pos=\"35\"\/><span class=\"id-r-component br\" data-pos=\"37\"\/>Congress leader Jairam Ramesh shared Adhikary\u2019s post on X writing, \u201cIn today\u2019s developments on Mantri Pradhan\u2019s Ministry of Scandals, the answer sheets of 2 million CBSE Grade 12 students have been shown to be available in the public domain. This is a data breach of monumental proportions and it compromises the privacy of 2 million students,\u201d Ramesh wrote.<span class=\"id-r-component br\" data-pos=\"39\"\/><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/education\/news\/cbse-vs-student-board-admits-vulnerabilities-after-teen-hacker-exposes-website-flaws\/articleshow\/131420668.cms\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Central Board of Secondary Education (CBSE) on Sunday said it has contained vulnerabilities identified in the OnMark portal of its service provider and is working with cybersecurity experts to further strengthen the system.The board also thanked ethical hackers and members of the public who brought the issues to its notice. \u201cWe are grateful to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":15183,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[264],"tags":[],"class_list":["post-15182","post","type-post","status-publish","format-standard","has-post-thumbnail","category-education"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/15182","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/comments?post=15182"}],"version-history":[{"count":0,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/posts\/15182\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media\/15183"}],"wp:attachment":[{"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/media?parent=15182"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/categories?post=15182"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/banitoday.com\/hi\/wp-json\/wp\/v2\/tags?post=15182"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}