Cyber Researcher Exposes Major Data Breach in JEE Advanced 2026 Portal
A significant cybersecurity flaw in the official portal for JEE Advanced 2026 has been uncovered, potentially exposing the personal information of nearly two lakh candidates. The vulnerability, which was identified by a 16-year-old security researcher, has since been addressed by the organizing institute, IIT Roorkee.
How the Security Flaw Was Discovered
The issue was brought to light by a user on the social media platform X, operating under the handle @DarthKermy72747. The researcher reported that the public cloud storage configuration associated with the JEE Advanced 2026 results infrastructure contained a critical misconfiguration. This technical error allowed sensitive candidate data to be accessed publicly without any form of login or authentication.
According to the researcher’s findings, the misconfiguration left a massive volume of confidential records exposed. This included the result files of approximately 179,000 students and the admit card PDFs of roughly 187,000 candidates. These documents contained highly personal details such as full names, dates of birth, and registered mobile numbers, all of which were accessible to anyone who knew where to look.
IIT Roorkee’s Swift Response
Upon receiving the alert, IIT Roorkee moved quickly to address the situation. The institute acknowledged the technical lapse and initiated immediate corrective measures to secure the vulnerable data.
Following the successful resolution of the issue, IIT Roorkee publicly expressed its gratitude to the young researcher. In an official statement, the institute thanked the researcher for bringing the cloud storage configuration error to their attention, noting that the problem was being resolved on a priority basis. The statement also clarified that the exposed data was in a read-only format, meaning it could not be altered or tampered with, thereby limiting the potential for misuse. The institute commended the researcher for conducting responsible and ethical security research.
What This Means for Candidates
For the lakhs of students who appeared for JEE Advanced 2026, this incident serves as a reminder of the importance of data security in high-stakes examinations. While the breach was a serious concern, the quick action taken by IIT Roorkee and the ethical approach of the researcher helped mitigate what could have been a far more damaging situation.
Key points regarding the incident include:
- The data exposure was caused by a misconfigured public cloud storage setting.
- No authentication was required to access the exposed information.
- Personal details like names, birth dates, and phone numbers were at risk.
- The data was read-only, preventing any unauthorized modifications.
- IIT Roorkee fixed the flaw promptly after being notified.
The incident highlights the growing role of independent cybersecurity researchers in safeguarding digital infrastructure. It also underscores the need for robust security protocols, especially for platforms handling the sensitive data of millions of students across the country.
