- By Kamakshi Bishnoi
- Sun, 31 May 2026 05:46 PM (IST)
- Source:JND
In a significant development to the OSM Portal row, the education department has intensified its probe, with the board now deploying cybersecurity experts from government agencies as well as the Indian Institutes of Technology (IITs) to strengthen the portal and address potential security gaps.
The row erupted after a 19-year-old hacker claimed to have identified vulnerabilities in the board’s On-Screen Marking (OSM) system used for digital evaluation of answer sheets. The Central Board of Secondary Education (CBSE) in a statement said that it is “closely monitoring the situation.
In its official statement shared on social media, CBSE said it is actively working to secure the system and has already contained the reported issues. The board stated, "The identified vulnerabilities have been contained, and other exploitable weaknesses are being ruled out."
We have been closely monitoring the vulnerabilities in the OnMark portal of our service provider that are being flagged in the public domain. An expert team of cybersecurity professionals has been deployed over the last few days from across various arms of the government as well…
— CBSE HQ (@cbseindia29) May 31, 2026
It also acknowledged contributions from independent researchers and ethical hackers, adding that some of them have been directly contacted by the authorities.
The controversy began after 19-year-old Nisarga Adhikary, a self-described “hobbyist cybersecurity researcher,” claimed he discovered serious flaws in the OSM portal earlier this year and reported them to CERT-In.
In his detailed blog post and social media thread, he alleged that sensitive weaknesses in the system could allow unauthorised access and manipulation of examiner-level controls. He reportedly claimed, "master password" was found embedded within the website’s JavaScript code, which could potentially bypass authentication checks.
He further explained his findings, saying, “I started examining the special logic for username, password, and OTPs and how it's processed. When examining that, I found a master password.”
According to him, this access could potentially allow deep system-level entry, including the ability to alter evaluation data.
Claims of bypassing security checks
The researcher also alleged that authentication was not fully server-secured, claiming OTP validation could be inspected through browser-level processes.
He said, “I started examining the special logic for username, password, and OTPs and how it's processed. When examining that, I found a master password.”
He further added that certain password reset functions did not require proper verification of old credentials, making the system vulnerable to manipulation.
The CBSE, however, stated that the system on which the actual Class 12 board exams are evaluated have not been breached. The portal stated in the viral post is just a test environment with sample or dummy data, on which an evaluation has not been carried out.
Increasing scrutiny on OSM system
This follows increased scrutiny of the new digital evaluation system introduced by the CBSE. Students had earlier expressed concerns about technical errors, mixed-up scans, and portal errors in the post result evaluations.
The board maintained that the system is continuously audited for security and upgraded to make it reliable.
