'Anyone can download': Teen hacker alleges CBSE answer sheets were exposed online
Days after alleging security flaws in CBSE’s digital evaluation system, 19-year-old ethical hacker Nisarga Adhikary has claimed that scanned answer sheets and question papers linked to the board were publicly accessible.
In a post on X, Adhikary alleged that an AWS bucket containing 2026 answer sheets and question papers could be accessed without authentication. “CBSE people didn't configure their AWS bucket properly and now we can paginate & enumerate all their media which has 2026 answersheets & question papers. ListObjectsV2 works without any auth and the bucket root is listable too — anyone on the internet can download any scanned booklet — across institutions. Multiple institutions are using the same bucket, insanely insecure,” he wrote.
According to Adhikary, the issue stemmed from a cloud storage configuration that allowed users to browse and download files without logging in or providing credentials. He also claimed that multiple institutions were using the same storage bucket, increasing the scale of the alleged exposure.
Screenshots shared by Adhikary appeared to show scanned answer booklets arranged in a file directory.
Congress leader Jairam Ramesh shared Adhikary’s post on X writing, “In today’s developments on Mantri Pradhan’s Ministry of Scandals, the answer sheets of 2 million CBSE Grade 12 students have been shown to be available in the public domain. This is a data breach of monumental proportions and it compromises the privacy of 2 million students,” Ramesh wrote.
The allegations come shortly after Adhikary claimed to have found several vulnerabilities in CBSE’s On-Screen Marking (OSM) portal. In a blog post titled “Exposing Critical Vulnerabilities in CBSE’s On-Screen Marking Portal”, he said he discovered the issues on February 25 and reported them to CERT-In before making them public.
“I was able to log in as an examiner and reach the evaluation dashboard, where I could view and edit marks,” Adhikary wrote in the blog. He also alleged that OTP verification could be bypassed and that several reported issues remained unpatched for an extended period.
As the claims gained traction, users reported that the OSM portal had become temporarily inaccessible. CBSE later responded to the allegations, stating that the URL cited in social media posts was not the portal used for actual evaluation work.
“At the outset, it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post,” CBSE said in a statement posted on X.
The board further stated that the website identified by Adhikary was only a testing platform containing sample data. “There are no actual evaluation data, marks or other data held on that portal. The Board emphasises that no security breaches have come to light on the Portal deployed for the actual evaluation work,” the statement added.
Ready to navigate global policies? Secure your overseas future. Get expert guidance now!
According to Adhikary, the issue stemmed from a cloud storage configuration that allowed users to browse and download files without logging in or providing credentials. He also claimed that multiple institutions were using the same storage bucket, increasing the scale of the alleged exposure.
Screenshots shared by Adhikary appeared to show scanned answer booklets arranged in a file directory.
The allegations come shortly after Adhikary claimed to have found several vulnerabilities in CBSE’s On-Screen Marking (OSM) portal. In a blog post titled “Exposing Critical Vulnerabilities in CBSE’s On-Screen Marking Portal”, he said he discovered the issues on February 25 and reported them to CERT-In before making them public.
“I was able to log in as an examiner and reach the evaluation dashboard, where I could view and edit marks,” Adhikary wrote in the blog. He also alleged that OTP verification could be bypassed and that several reported issues remained unpatched for an extended period.
As the claims gained traction, users reported that the OSM portal had become temporarily inaccessible. CBSE later responded to the allegations, stating that the URL cited in social media posts was not the portal used for actual evaluation work.
“At the outset, it is clarified that the Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post,” CBSE said in a statement posted on X.
The board further stated that the website identified by Adhikary was only a testing platform containing sample data. “There are no actual evaluation data, marks or other data held on that portal. The Board emphasises that no security breaches have come to light on the Portal deployed for the actual evaluation work,” the statement added.
Ready to navigate global policies? Secure your overseas future. Get expert guidance now!
Comments (1)
A
Amer HaleemMost Interacted
5 hours ago
Will be fixed is what our education minister will say, wonder why is he still in the chair.If this does not bother him, what does?...Read More
Reply
0
Reply
Popular from Education
- KCET 2026 results expected shortly as KEA prepares UGCET scorecard release at karresults.nic.in
- Why global universities are expanding into India: University of Aberdeen’s Mumbai strategy
- JEE Advanced 2026 topper Shubham Kumar: 'No social media helped me secure AIR 1'
- AP EAMCET 2026 result out today at cets.apsche.ap.gov.in; here's how to check scorecards and admission ranks
- MHT CET 2026 result date: Maharashtra State CET Cell to announce results soon- Here's how to check scores
end of article
Trending Stories
- UP Board Class 10th, 12th result 2026 expected soon says DigiLocker: Check expected date and steps to download scorecards
- Karnataka SSLC Class 10th result 2026 expected to be released in early May, DigiLocker notice says "soon:" Check complete details here
- NEHU Result 2026 declared: How to check your scorecard; complete details here
- IPMAT admit card 2026 released for IIM Indore and Rohtak: Check steps to download hall tickets here
- Assam HS Class 12th result 2026 likely to be released soon, says DigiLocker notice: Here are steps to download scorecards
- “Do not go with a lot of targets in your mind,” says Rohit Gupta, CAO at PhysicsWallah: Mindset shift NEET aspirants need before exam day
- JKBOPEE CET admit card 2026 released at jkbopee.gov.in: Direct link to download hall tickets here
Featured in education
- From ghunghat to gavel: How Barmer's ‘Judge Bahu’ Deepu Kanwar defied tradition to become a Civil Judge
- AP EAMCET 2026 result out today at cets.apsche.ap.gov.in; here's how to check scorecards and admission ranks
- CTET September 2026 registration ends soon at ctet.nic.in: Check exam pattern, direct link to apply
- TNEA registration deadline extended till June 5: Check direct link to apply here
- AISA protest over exam irregularities ends in detentions, student body seeks Dharmendra Pradhan's resignation
- Amrita BTech CSAP Counselling 2026 Round 1 seat allotment result released at aeee.amrita.edu: Direct link to download here
Photostories
- From the elite class's hobby to contemporary decorative: How did bonsai making turn into a modern-day art form?
- Love quote of the day by Louis de Bernières: ‘Love is not breathlessness; it’s not excitement’
- How Ranveer Singh and Farhan Akhtar’s friendship exploded over ‘Don 3’: Inside Rs 45 crore fallout that led to FWICE directive
- The rare and unique snakes of the Amazon forests
- 7 best low-maintenance plants for kitchen counters and windowsills
- Success quote of the day by Frank Sinatra: 'The best revenge is massive success'
- 9 stunning places to visit in Lahaul Valley after crossing the Atal Tunnel in Himachal Pradesh
- Virat Kohli and Anushka Sharma: 5 adorable moments of the couple celebrating RCB’s back-to-back IPL 2026 championship win
- Meet the 35 MLAs sworn in as ministers in West Bengal's massive cabinet expansion
- 5 relationship books that will actually change how you love (no cliches allowed)
Up Next
Follow Us On Social Media