Ethical hacker Nisarga Adhikary exposed multiple security vulnerabilities in India's Central Board of Secondary Education's OnMark digital evaluation platform, revealing that 9.3 million rows of sensitive student data including answer sheets were unprotected and accessible without authentication.
In February 2026, 19-year-old ethical hacker Nisarga Adhikary discovered and reported security vulnerabilities in the Central Board of Secondary Education's (CBSE) OnMark digital evaluation platform operated by technology vendor COEMPT Eduteck. After initially reporting the issues on February 25, 2026, Adhikary found that while CBSE took the portal down within 3-4 days, six to seven vulnerabilities remained active and exploitable. On May 30, 2026, Adhikary successfully hacked into the CBSE's Principals dashboard, accessing 9.3 million columns and rows of sensitive student data including images of answer sheets that were unprotected and could be tampered with. The hacker revealed that COEMPT Eduteck had stored 2026 answer sheets and question papers in Amazon Web Services buckets without authentication, and that sensitive student data including personal information was being processed by Google's Gemini AI in automation scripts without student consent. Following public disclosure of these vulnerabilities, CBSE acknowledged the issues on May 31, 2026, stating the vulnerabilities had been contained and that cybersecurity experts from government agencies and Indian Institutes of Technology had been deployed to fortify the systems.
Domain classification, causal taxonomy, severity scores, and national security assessments were LLM-classified and may contain errors.
Vulnerabilities that can be exploited in AI systems, software development toolchains, and hardware, resulting in unauthorized access, data and privacy breaches, or system manipulation causing unsafe outputs or behavior.
Human
Due to a decision or action made by humans
Unintentional
Due to an unexpected outcome from pursuing a goal
Post-deployment
Occurring after the AI model has been trained and deployed