Hi, I want to give a talk on how I hacked India's largest exam system (CBSE). i'll walk through how i found the vulnerability, the technical mistakes that made exploitation possible, the disclosure process with cert-in and relevant stakeholders, and the challenges researchers face when reporting security flaws in public institutions.
the talk will also explore larger questions: why do critical systems continue to fail basic security reviews? what incentives exist for researchers to report vulnerabilities responsibly? and how can india build a healthier relationship between security researchers and public-sector organizations?
also would like to highlight my usage of open source tools and how critical infrastructure can benefit from FOSS.
A major focus of the session is demonstrating how accessible open source tooling can be used to evaluate the security of large-scale public infrastructure. Throughout the assessment I relied primarily on FOSS tools for reconnaissance, enumeration, testing and validation, highlighting how developers, students and organizations can build effective security workflows without expensive commercial software.
Link: https://ni5arga.com/blog/posts/hacking-cbse
i will walk the audience through various vulnerabilities like hardcoded master password in JS bundle, client-side OTP validation, missing route guards, bypassing auth with fake tokens into localStorage, password reset without old password verification, systemic IDOR across the entire API, SQL injection to RCE via xp_cmdshell, publicly listable S3 bucket, re-evaluation portal PII leak etc.
A lot of famous personalities and organizations like [Deedy Das](https://x.com/deedydas/status/2059131444346425354), [Satish Acharya](https://x.com/satishacharya/status/2059224148845768781), [Internet Freedom Foundation](https://x.com/internetfreedom/status/2059267815690088454) tweeted about it & this blog has been featured in news reports by multiple media outlets:
- [India Today](https://www.indiatoday.in/education-today/news/story/cbse-osm-portal-vulnerability-claims-surface-with-teens-detailed-blog-post-2917243-2026-05-26)
- [BBC News](https://www.bbc.com/news/articles/cy42e8eljpno)
- [NDTV](https://www.ndtv.com/education/cbse-osm-portal-had-critical-vulnerabilities-ethical-hacker-told-ndtv-he-alerted-board-months-earlier-11550090)
- [Times of India](https://timesofindia.indiatimes.com/education/news/cbse-faces-fresh-scrutiny-after-teen-researcher-alleges-critical-flaws-in-osm-portal-claims-class-12-marks-could-be-altered/articleshow/131330616.cms)
- [The Hindu BusinessLine](https://www.thehindubusinessline.com/news/education/government-should-take-cybersecurity-more-seriously-says-ethical-hacker-on-cbse-osm-flaws/article71024371.ece)
- [ThePrint](https://theprint.in/feature/19-student-hacked-cbses-osm-portal-vulnerabilities/2942305/)
- [News18](https://www.news18.com/viral/ex-google-engineer-calls-out-cbses-osm-portal-absolute-embarrassment-after-hacker-exposes-major-security-flaws-ws-l-10113830.html)
- [Hindustan Times](https://www.hindustantimes.com/htcity/leisure/this-teen-hacked-into-cbse-s-osm-portal-while-preparing-for-boards-says-this-is-just-a-hobby-101779875877374.html)
- [Financial Express](https://www.financialexpress.com/india-news/cbse-portal-very-easy-to-exploit-class-12-hacker-says-he-didnt-expect-amateur-vulnerabilities-exclusivenbsp/4252095/)
- [Times Now](https://www.timesnownews.com/education/exclusive-i-have-enough-proof-19-year-old-defends-claims-of-security-flaws-in-cbse-osm-portal-article-154408591)
- [CNBC TV18](https://www.cnbctv18.com/videos/education/cbse-on-screen-marking-controversy-hacker-security-claims-experts-divided-19914723.htm)
- [Moneycontrol](https://www.moneycontrol.com/technology/big-blunder-how-a-cbse-student-uncovered-a-security-flaw-in-a-national-exam-portal-article-13932552.html)
- [IFF Blog](https://internetfreedom.in/when-the-exam-itself-can-be-hacked-iff-writes-to-the-ministry-of-education-and-cert-in-on-the-cbse-on-screen-marking-disclosure/)
- [Medianama](https://www.medianama.com/2026/05/223-cert-in-vulnerabilities-cbse-online-marking-portal/)
- [Free Press Journal](https://www.freepressjournal.in/education/fpj-exclusive-meet-nisarga-the-19-year-old-ethical-hacker-who-flagged-alleged-cbse-portal-issues-in-february-2026)
- [Careers360](https://news.careers360.com/cbse-osm-portal-hacker-nisarga-adhikary-vulnerabilities-report-meaning-class-12-checking-result-onmark-co-in-cybersecurity)