'Anyone can download': Teen hacker alleges CBSE answer sheets were exposed online
Days after alleging security flaws in CBSE’s digital evaluation system, 19-year-old ethical hacker Nisarga Adhikary has claimed that scanned answer sheets and question papers linked to the board were publicly accessible.
In a post on X, Adhikary alleged that an AWS bucket containing 2026 answer sheets and question papers could be accessed without authentication. “CBSE people didn't configure their AWS bucket properly and now we can paginate & enumerate all their media which has 2026 answersheets & question papers. ListObjectsV2 works without any auth and the bucket root is listable too — anyone on the internet can download any scanned booklet — across institutions. Multiple institutions are using the same bucket, insanely insecure,” he wrote.
According to Adhikary, the issue stemmed from a cloud storage configuration that allowed users to browse and download files without logging in or providing credentials. He also claimed that multiple institutions were using the same storage bucket, increasing the scale of the alleged exposure.
Screenshots shared by Adhikary appeared to show scanned answer booklets arranged in a file directory.
Congress leader Jairam Ramesh shared Adhikary’s post on X writing, “In today’s developments on Mantri Pradhan’s Ministry of Scandals, the answer sheets of 2 million CBSE Grade 12 students have been shown to be available in the public domain. This is a data breach of monumental proportions and it compromises the privacy of 2 million students,” Ramesh wrote.
The allegations come shortly after Adhikary claimed to have found several vulnerabilities in CBSE’s On-Screen Marking (OSM) portal. In a blog post titled “Exposing Critical Vulnerabilities in CBSE’s On-Screen Marking Portal”, he said he discovered the issues on February 25 and reported them to CERT-In before making them public.
“I was able to log in as an examiner and reach the evaluation dashboard, where I could view and edit marks,” Adhikary wrote in the blog. He also alleged that OTP verification could be bypassed and that several reported issues remained unpatched for an extended period.
As the claims gained traction, users reported that the OSM portal had become temporarily inaccessible. CBSE later responded to the allegations, stating that the URL cited in social media posts was not the portal used for actual evaluation work.
“At the outset, it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post,” CBSE said in a statement posted on X.
The board further stated that the website identified by Adhikary was only a testing platform containing sample data. “There are no actual evaluation data, marks or other data held on that portal. The Board emphasises that no security breaches have come to light on the Portal deployed for the actual evaluation work,” the statement added.
Ready to navigate global policies? Secure your overseas future. Get expert guidance now!
According to Adhikary, the issue stemmed from a cloud storage configuration that allowed users to browse and download files without logging in or providing credentials. He also claimed that multiple institutions were using the same storage bucket, increasing the scale of the alleged exposure.
Screenshots shared by Adhikary appeared to show scanned answer booklets arranged in a file directory.
The allegations come shortly after Adhikary claimed to have found several vulnerabilities in CBSE’s On-Screen Marking (OSM) portal. In a blog post titled “Exposing Critical Vulnerabilities in CBSE’s On-Screen Marking Portal”, he said he discovered the issues on February 25 and reported them to CERT-In before making them public.
“I was able to log in as an examiner and reach the evaluation dashboard, where I could view and edit marks,” Adhikary wrote in the blog. He also alleged that OTP verification could be bypassed and that several reported issues remained unpatched for an extended period.
As the claims gained traction, users reported that the OSM portal had become temporarily inaccessible. CBSE later responded to the allegations, stating that the URL cited in social media posts was not the portal used for actual evaluation work.
“At the outset, it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post,” CBSE said in a statement posted on X.
The board further stated that the website identified by Adhikary was only a testing platform containing sample data. “There are no actual evaluation data, marks or other data held on that portal. The Board emphasises that no security breaches have come to light on the Portal deployed for the actual evaluation work,” the statement added.
Ready to navigate global policies? Secure your overseas future. Get expert guidance now!
Comments
Be the first to share a thought and become theFirst Voiceof this News Article
Popular from Education
- Can a six-month programme from IIT Delhi close India's most urgent tech skills gap?
- AP SBTET diploma results 2026 released for C23, C20, C16 schemes at sbtetap.gov.in; direct download link here
- IMU CET 2026 result expected to be released today at imu.edu.in: Check steps to download rank card
- How Habitat Hustle 2026 turned competition into a lesson in leadership
- UP Police Constable Exam 2026: Exam city intimation slip shortly at upprpb.in; exam from June 8
end of article
Trending Stories
- UP Board Class 10th, 12th result 2026 expected soon says DigiLocker: Check expected date and steps to download scorecards
- Karnataka SSLC Class 10th result 2026 expected to be released in early May, DigiLocker notice says "soon:" Check complete details here
- NEHU Result 2026 declared: How to check your scorecard; complete details here
- IPMAT admit card 2026 released for IIM Indore and Rohtak: Check steps to download hall tickets here
- Assam HS Class 12th result 2026 likely to be released soon, says DigiLocker notice: Here are steps to download scorecards
- “Do not go with a lot of targets in your mind,” says Rohit Gupta, CAO at PhysicsWallah: Mindset shift NEET aspirants need before exam day
- JKBOPEE CET admit card 2026 released at jkbopee.gov.in: Direct link to download hall tickets here
Featured in education
- CBSE vs student: Board admits vulnerabilities after teen hacker exposes website flaws
- 'Has time to speak about Mangoes': Rahul targets PM for not addressing CBSE controversy
- NABARD Development Assistant 2026: Mains results out soon; here's how to check
- Madhya Pradesh extends Teachers' summer break amid heatwave; schools to reopen on June 16
- Delhi CM SHRI school Class 11 admission test result 2026 released at edudel.nic.in: Direct link to download scorecards here
- UPSC CSE prelims 2026 answer key objection window closes today: Check steps to raise challenges here
Photostories
- 6 types of litchi available in India and how to pick the sweetest one at the market
- 7 powerful reverse psychology tricks that usually work
- From T. Rex to Spinosaurus: Meet the most terrifying dinosaurs to ever walk the earth, dominating the prehistoric world with unmatched size, strength, and hunting power
- Kriti Sanon is serving flirty luxe with emerald envy in this Rs 67,000 designer mini dress for ‘Cocktail 2' promotions
- Juhi Chawla’s son Arjun to Ananya Panday’s sister Rysa Panday: Celebrity kids who marked major academic milestones in 2026
- 7 factors making India’s coastal towns real estate investment hotspots
- Archana Puran Singh’s son Aaryamann gives a glimpse of his new approximately Rs 50 crore house in Madh Island; he shares an important update
- 5 surprising ways yoga changes your mind and soul (not just your body)
- Success quote of the day by Virat Kohli: “Whatever you want to do, do it with...”
- From Seals to Whales: 7 animals that produce thickest milk on earth
Up Next
Follow Us On Social Media