
In February 2026, 19-year-old cybersecurity researcher Nisarga Adhikary identified multiple security vulnerabilities in CBSE's On-Screen Marking (OSM) portal within 30 minutes of examination. According to reports from Business Standard, the flaws were serious enough to potentially allow individuals with basic technical knowledge to impersonate examiners, reset passwords, and manipulate student marks on a national scale. The vulnerabilities remained largely confined to niche cybersecurity discussions until claims went viral on X on May 25. Tech investor and prominent X voice Deedy Das amplified the story, calling it 'an absolute embarrassment', with many users expressing deep concern for students who have been studying for years to have their futures determined by a teenager with Firefox DevTools. Adhikary recently completed Class 12 and describes himself as a hobbyist cybersecurity researcher who has previously worked on bug bounty and vulnerability-hunting projects, having studied in Delhi and built cybersecurity tools.
As reported by Business Standard, Adhikary discovered a hardcoded 'master password' embedded in the frontend code that allegedly allowed OTP verification to be bypassed entirely. He also claimed that OTP validation was handled on the client side rather than being securely processed on the server, making it vulnerable to manipulation. According to Nisarga's technical blog, the breaches included a master password leaked in client-side JavaScript code, bypass of client-side 2FA/OTP validation, tokenless access to the entire internal admin dashboard, ability to change any user's password without knowing the old one, and IDOR (Insecure Direct Object Reference) vulnerability allowing anyone to impersonate users and edit exam marks. Adhikary explained that "it was one of the easiest hacks of my life. You don't even need to know programming, you just need to know control point F and need to know the logic. That was the master vulnerability." He also claimed that anyone can create a new password without entering the old password, and that examiner identities can be manually edited through browser storage values, allowing someone to impersonate teachers, access their details, and potentially alter marks or evaluation records. The West Bengal native stated that "none of this required sophisticated exploitation. The hardest part was reading a JavaScript file and editing a couple of values in DevTools."
According to Business Standard, CBSE issued a clarification rejecting claims that its live evaluation portal had been compromised, stating that screenshots and URLs shared by Adhikary related to a 'testing site' containing sample data used for internal review. The board maintained that no actual student evaluation data or marks were stored on the platform. However, on Tuesday, the CBSE website was taken offline entirely, triggering massive online outrage and embarrassment for the national examination body. On May 26, Adhikary disputed this clarification and posted video evidence on X, claiming that the exposed master password could still allow unauthorised access to systems containing production data. Nisarga stressed in his blog that "the client cannot be trusted, ever," and that these were basic security mistakes. For the next three days, the portal was down and Adhikary claimed that during this time, only one glitch had been fixed. The teen flagged six high-severity vulnerabilities that were still present on the site, including one on the master password. After discovering the vulnerabilities, Adhikary sent emails to multiple authorities, including the Indian Computer Emergency Response Team (CERT-In) and other government-linked cybersecurity contacts, but did not receive satisfactory response. "It's very disrespectful, to be honest, to not get a response after following up several times," he added, noting that "there are companies who take lakhs of rupees to do this kind of audits and I'm doing it for free just to help them."
As reported by Business Standard, the CBSE introduced the On-Screen Marking system (OSM) for Class 12 board examinations from 2026, where answer sheets are scanned and evaluated digitally instead of being assessed physically. The platform is developed by Coempt EduTeck Pvt Ltd and uses the OnMark system, which is also deployed by other educational institutions. The board stated the process is designed to reduce manual intervention and minimise human error in evaluation. However, the system is currently facing severe backlash with thousands of students reporting unexpectedly low marks, mental stress, and serious evaluation errors in the 2026 Class 12 board results. Many parents and students have taken to social media alleging that the new OSM system failed them, with one user remarking, "Imagine studying 14 years for board exams just for some teenager with Firefox DevTools to decide your future." Students have complained about many irregularities in the new system introduced by the CBSE this year, with the overall result witnessing a dip and many students complaining of scoring low marks. Many asked for the scanned answer sheets and found that the copy they submitted was missing or, in many cases, the handwriting was different. During the re-evaluation process, students faced systemic chaos including payment gateway crashes, server failures, and receiving incorrect or blurred answer sheets. The chaos has been so severe that with re-evaluation deadlines passing, many students remain without a resolution, raising serious questions about the digital infrastructure's reliability.
According to Business Standard, Union Education Minister Dharmendra Pradhan directed CBSE to urgently address glitches in the post-result process and strengthen the system's digital infrastructure with support from IIT experts and public sector banks. Pradhan stated on May 24 that "student interests remain paramount, and all corrective measures must be undertaken by CBSE on priority to ensure a transparent, efficient and student-friendly system." After discovering the vulnerabilities, Adhikary initially chose not to make the vulnerabilities public and instead reported them to CERT-In, before posting anything online. After receiving no response from agencies regarding his findings for months, Adhikary wrote a blog and shared screen recordings, technical details, and demonstrations of the flaws. His post went viral, the CBSE platforms went down, and the flaws still remain. CBSE denied that its OSM portal was hacked, issuing a detailed clarification on X on Tuesday. The board wrote that "it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post." It added that the URL was "the testing site only with sample data for internal testing and review purposes" and that there are no actual evaluation data, marks or other data held on that portal. However, Adhikary claimed that the URL in CBSE's post was "not even a real domain" and that it was directing users to his blog. Calls for accountability have grown loud, with users questioning the lack of mainstream media coverage and demanding transparency on both evaluation fairness and digital security.