CBSE Dismisses Claims of OSM Portal Breach, Calls Viral URL a Testing Platform
The Central Board of Secondary Education has officially responded to allegations made by a 19-year-old cybersecurity researcher who claimed to have compromised the board’s On-Screen Marking system earlier this year. In a formal statement, CBSE clarified that the URL in question was never part of the live evaluation infrastructure but rather a dedicated testing environment with no access to real student data or actual assessment records.
What Sparked the Controversy?
The dispute began when cybersecurity researcher Nisarga Adhikari published a detailed technical blog post claiming to have uncovered multiple critical vulnerabilities in CBSE’s On-Screen Marking portal. According to his findings, these flaws could potentially allow unauthorized access to examiner accounts and even enable manipulation of student scores.
Adhikari stated that he first identified these security weaknesses on February 25 and, following responsible disclosure practices, reported his findings to the Indian Computer Emergency Response Team before making any public announcement. His claims quickly gained traction on social media platform X, prompting widespread concern about the security of the board’s digital infrastructure.
Alleged Vulnerabilities Detailed
In his technical write-up, Adhikari outlined several specific security concerns that he said existed within the portal’s architecture:
- A hardcoded master password embedded directly in the portal’s JavaScript code
- Client-side OTP verification that could potentially be bypassed
- Weaknesses in the password reset functionality
- A systemic Insecure Direct Object References vulnerability that could expose unauthorized data
The researcher maintained that these issues were not theoretical but demonstrated practical security failures in the system’s design. He also claimed to possess screen recordings and official acknowledgement from CERT-In as evidence supporting his findings.
CBSE’s Official Response
In response to the growing controversy, CBSE issued a formal clarification addressing the allegations directly. The board stated that the portal referenced in the researcher’s claims was never connected to the actual evaluation system used for grading answer sheets. According to CBSE officials, this particular website was created exclusively for internal testing and review purposes, containing only sample or dummy data.
The board emphasized that the genuine evaluation platform operates separately from any testing environments and has not experienced any security compromises. They further assured all stakeholders that the actual portal handling real answer sheets and student information is protected by robust security measures designed to prevent unauthorized access and maintain data integrity.
Researcher Challenges CBSE’s Explanation
Adhikari, however, was quick to challenge the board’s characterization of events. In a direct response to CBSE’s statement on social media, he raised pointed questions about how he was able to log in using what he described as production user data if the site was indeed only a testing environment. He reiterated that he has preserved screen recordings of his actions and holds official documentation confirming CERT-In’s acknowledgement of his reports.
Furthermore, the researcher alleged that similar vulnerabilities existed across multiple related subdomains, suggesting that the security issues were not isolated to a single testing platform but potentially affected a broader range of systems associated with the board’s operations.
Context of Previous Concerns
This latest controversy arrives amid heightened scrutiny of CBSE’s digital systems. Just weeks earlier, the board acknowledged a technical error that resulted in a Delhi student receiving another student’s physics answer sheet. While CBSE subsequently corrected the mistake and provided the proper document, the incident raised questions about the reliability of the board’s new digital evaluation infrastructure.
The On-Screen Marking system was introduced this year as part of CBSE’s broader initiative to streamline the Class 12 evaluation process and bring greater transparency to result preparation. The system was designed to digitize the marking workflow, allowing examiners to assess answer sheets electronically rather than through traditional paper-based methods.
Ongoing Investigation and Next Steps
In response to the security concerns, CBSE has commissioned a comprehensive review of the portal and its associated systems. Technical experts from two of India’s premier institutions, the Indian Institutes of Technology in Madras and Kanpur, have been tasked with conducting a thorough investigation into all aspects of the matter, including potential technical flaws, system failures, and possible cyber attacks.
The director of IIT Madras, V. Kamakoti, confirmed that the investigation will examine every angle thoroughly and noted that the portal has remained stable over the past 72 hours, suggesting no ongoing active threats at this time.
Adding to the institutional response, the Parliamentary Standing Committee on Education, Women, Children, Youth and Sports has summoned senior officials from both the Union Education Ministry and CBSE for a meeting scheduled on June 2. The committee intends to review the difficulties faced by students following the Class 12 results announcement and conduct a detailed examination of the On-Screen Marking system’s implementation and performance.
Broader Digital Infrastructure Reforms
In parallel with the OSM portal investigation, Union Education Minister Dharmendra Pradhan convened a meeting with senior representatives from four major public sector banks to discuss substantial improvements to CBSE’s payment gateway infrastructure. During this session, the minister directed the banks to collaborate with CBSE in developing a more robust payment protocol that would ensure timely transactions, provide immediate resolution of payment-related issues, and automatically process refunds in cases of duplicate or failed payments.
These coordinated actions signal a broader push by the education ministry to strengthen the digital backbone supporting the country’s examination systems. As the investigation into the alleged security breach continues, both CBSE and government authorities appear committed to addressing vulnerabilities and restoring confidence in the integrity of the evaluation process.
The coming weeks will likely provide further clarity on the technical findings from the IIT experts and the outcomes of the parliamentary committee’s review. For now, the central tension remains between the researcher’s claims of serious security flaws and the board’s insistence that its actual evaluation systems remain uncompromised and secure.
