๐Ÿ“ŠStalecollected in 58m

Indian Exam Board Patches Critical Grading Portal Vulnerabilities

PostLinkedIn
๐Ÿ“ŠRead original on Bloomberg Technology

๐Ÿ’กA reminder that critical infrastructure security often relies on external researchers; audit your own portals now.

โšก 30-Second TL;DR

What Changed

National exam board confirmed vulnerabilities in online grading infrastructure

Why It Matters

This incident highlights the critical need for rigorous penetration testing in educational infrastructure. It underscores how individual researchers play a vital role in identifying gaps in large-scale public sector systems.

What To Do Next

Audit your own public-facing web applications for common OWASP Top 10 vulnerabilities to prevent similar unauthorized access.

Who should care:Developers & AI Engineers

Key Points

  • โ€ขNational exam board confirmed vulnerabilities in online grading infrastructure
  • โ€ขSecurity flaws were identified by a teenage cybersecurity researcher
  • โ€ขThe board has implemented containment measures to secure the portal

๐Ÿง  Deep Insight

Web-grounded analysis with 13 cited sources.

๐Ÿ”‘ Enhanced Key Takeaways

  • โ€ขThe Indian exam board involved is the Central Board of Secondary Education (CBSE), and the vulnerabilities were identified by 19-year-old cybersecurity researcher Nisarga Adhikary in its On-Screen Marking (OSM) portal.
  • โ€ขThe critical flaws included a hardcoded master password embedded in publicly accessible JavaScript files, insecure client-side validation for OTP-based authentication, and Insecure Direct Object Reference (IDOR) vulnerabilities.
  • โ€ขNisarga Adhikary initially discovered and reported the vulnerabilities to CERT-In (Indian Computer Emergency Response Team) in February 2026, but the technical details became public in May 2026, with claims that some issues remained unpatched.
  • โ€ขWhile CBSE initially stated the vulnerabilities were confined to a testing environment, the board later confirmed on May 31, 2026, that it had contained vulnerabilities in the 'OnMark portal of its service provider' and was collaborating with cybersecurity experts from various government agencies and IITs to enhance system security.
  • โ€ขThis incident highlights broader cybersecurity challenges within India's digital examination infrastructure, occurring shortly after the National Testing Agency (NTA) cancelled the NEET-UG 2026 exam in May 2026 due to a paper leak, affecting over 22 lakh students.

๐Ÿ› ๏ธ Technical Deep Dive

  • Hardcoded master password: A master password string was found directly embedded within publicly accessible JavaScript files, potentially allowing attackers to bypass OTP-based authentication.
  • Insecure client-side validation: Critical OTP validation checks were handled on the client side rather than through secure server-side authentication, making them susceptible to bypass using basic browser developer tools.
  • Insecure Direct Object Reference (IDOR): Examiner and validator IDs were reportedly retrieved directly from browser session storage, enabling unauthorized users to manipulate identifiers and gain access to other accounts and student evaluations.
  • Password reset flaws: The portal's password reset mechanism allegedly allowed account credentials to be changed without verifying the original password.
  • Missing route protections: The system lacked adequate route protections, which could allow anonymous visitors to access internal pages without proper authentication.

๐Ÿ”ฎ Future ImplicationsAI analysis grounded in cited sources

Indian examination boards will face increased pressure to invest significantly in robust cybersecurity measures and infrastructure.
The recurring high-profile security incidents, including this CBSE vulnerability and the NTA paper leak, will compel government and educational bodies to prioritize and allocate more resources to secure digital examination platforms.
There will be a greater push for formalizing responsible disclosure programs and fostering collaboration with ethical hackers.
CBSE's eventual acknowledgment and thanks to ethical hackers indicate a growing recognition of the value of external security researchers in identifying and reporting vulnerabilities, potentially leading to more structured programs.
A national framework or standardized security audit protocols may be implemented for all major examination conducting bodies in India.
The systemic nature of some vulnerabilities and the involvement of multiple national exam boards in recent controversies could lead to a more unified and stringent approach to cybersecurity governance across the education sector.

โณ Timeline

2017-11
National Testing Agency (NTA) established to conduct major entrance exams in India.
2024
K. Radhakrishnan committee formed to recommend reforms for the NTA following a NEET crisis.
2026-02
Nisarga Adhikary discovers and reports critical vulnerabilities in CBSE's On-Screen Marking (OSM) portal to CERT-In.
2026-05-03
NEET-UG 2026 examination conducted by the National Testing Agency (NTA).
2026-05-12
NTA cancels the NEET-UG 2026 exam due to allegations of a paper leak, affecting over 22 lakh students.
2026-05-26
Technical details of CBSE's OSM portal vulnerabilities, reported by Nisarga Adhikary, go viral on social media, prompting public concern and an initial clarification from CBSE.
2026-05-31
CBSE confirms containment of vulnerabilities in the OnMark portal of its service provider and announces collaboration with cybersecurity experts from government agencies and IITs.

๐Ÿ“Ž Sources (13)

Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.

  1. collegeadmission.in
  2. indiatimes.com
  3. prameyanews.com
  4. financialexpress.com
  5. bumppy.com
  6. indiatimes.com
  7. hindustantimes.com
  8. indiatimes.com
  9. easemyprep.in
  10. riceias.com
  11. visionias.in
  12. indiatimes.com
  13. deccanherald.com
๐Ÿ“ฐ

Weekly AI Recap

Read this week's curated digest of top AI events โ†’

๐Ÿ‘‰Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: Bloomberg Technology โ†—