Quick overview – click for full details
Concise summary of key points
Quick overview – click for full details
Concise summary of key points
In one line
A 19-year-old cyber security researcher claims to have hacked CBSE’s OSM portal, but the board denies any breach has taken place.
Key points
• Hacker claims
A 19-year-old cyber security enthusiast, Nisarga, claimed to have exploited multiple vulnerabilities in CBSE’s OSM portal in February 2024, including encrypted passwords and weak authentication, and reported them to CERT-In.
• CBSE disclaimer
CBSE denied any compromise of its current assessment portal, stating that the referred URL was a test page with sample data and no live information.
• Weaknesses of the portal
The alleged issues included client-side OTP authentication, weak path protection, password reset errors, and insecure direct object reference (IDOR) vulnerabilities that allow user impersonation.
• Government intervention
The Union Education Ministry has deputed experts from IIT Madras and IIT Kanpur to audit the technical infrastructure of the OSM system.
Processed with AI. Reviewed by DH Digital Team.
I had hacked OSM (On Screen Marking Portal) of CBSE in February and reported the vulnerabilities to CERT-In but they were not able to fix most of them.
I’ve written a detailed blog post about it here: https://t.co/qyT23GkTEJ
— nisarga (@ni5arga) May 22, 2026
Clarification regarding CBSE OSM portal compromise claim
In a post made by a social media user, it has been claimed that CBSE On Screen Marking (OSM) has the URL: https://t.co/cuLrvsxzOH was compromised by him on 26.02.2026. This has also created the basis for some…
— CBSE Headquarters (@cbseindia29) May 26, 2026
🧵 (1/4) CBSE is claiming that the portal was not compromised, but here is some video evidence to prove that there was indeed a security bug on their side that leaked the master password and could be used to gain unauthorized access to the portal that had production data pic.twitter.com/3Kn5uZnEZc
— nisarga (@ni5arga) May 26, 2026
Published May 27, 2026, 06:30 IS





