Who is Nisarga Adhikary, ethical hacker who exposed vulnerabilities in CBSE’s OnMark Portal

Who is Nisarga Adhikary, ethical hacker who exposed vulnerabilities in CBSE’s OnMark Portal

Find out who is Nisarga Adhikary, a 19-year-old boy, who hackedinto CBSE’s server and accessed various important files

Not sure of what we’re talking about? Here is everything you need to know about the controversial hacking scandal and the individual behind it.

Who is Nisarga Adhikary, ethical hacker who exposed vulnerabilities in India’s CBSE’s OnMark Portal 

What Exactly Happened?

Ethical Hacker Nisarga Adhikary who exposed vulnerabilities in CBSE’s OnMark portal, exposed serious security lapses, including easily guessable passwords, unsecured databases, and public storage buckets that allegedly exposed sensitive data such as answer sheets and student credentials. He also raised concerns over data privacy and sovereignty, alleging that CBSE’s tech vendor, COEMPT Eduteck, processed sensitive student data using Google’s Gemini and stored answer sheets in public Amazon Web Services buckets without the adequate security checks.

Earlier, social media platforms were buzzing with viral claims that someone had hacked into CBSE’s server and accessed various files including examination-related files.

Not just that, Adhikary went as far as to share the images online on his official X/Twitter account, wherein he stated that “anyone on the internet can download any scanned booklet” while adding “insanely insecure.”

This matter came into the spotlight amidst the ongoing controversy of CBSE paper leak and digital evaluation ecosystem of the central board.

Advertisement

What Did Adhikary Reveal?

Reportedly, the teenager driven by his curiosity examined the portal’s backend code, however, within an hour he ended up uncovering major systematic vulnerabilities.

Allegedly, after accessing the server, Nisarga immediately found the master password sitting in plain site in Javabundle. He alleged that using this password anyone could’ve bypass the Mandatory OTP verification.

This allows any user, who’s trying to access, to log into the any examiner’s account across India, given if they knew the user ID of the particular examiner.

Additionally, he also revealed that a linked AWS service of CBSE, which is a storage bucket, where millions of scanned answer sheets and question papers of 2026 were publicly viewable and downloadable without any authentication.

Advertisement

To prove his claims, the teenager even shared a screen recording of the now-viral “bad apple” silhouette animation running directly on CBSE-linked dashboard.

Who is Nisarga Adhikary?

Nisarga Adhikary is a 19-year-old self taught cybersecurity researcher.

The ethical hacker is from Siliguri, West Bengal. He came to spotlight in May 2026, after he discovered the critical security flaws in CBSE’s newly launched OSM portal, a digital system scanner used to grade scanned Class-12 board answer sheets.

At the time of hacking and discovery, the teenager himself was just class-12 student, who have just given his own board exams.

Reportedly, Nisarga Adhikary began programming as a young teenager, and despite recently graduating from High School, he already works for Wavelength, a tech firm based in Bengaluru, as a remote software engineer.

Advertisement