‹ Back to Home

CERT-In Told Researcher to Halt CBSE Flaw Disclosure

Nisarga Adhikary found CBSE portal bugs, reported to CERT-In, waited 3-4 weeks, went public, and got a cease-and-desist. Here is why India needs a bulletproof vulnerability disclosure policy.

Keerthika 5 min read
Follow on Google
Security CERT-In Told Researcher to Halt CBSE Flaw Disclosure 5 min left Follow on Google
CERT-In Told Researcher to Halt CBSE Flaw Disclosure

TamilTech AI summary

Nisarga Adhikary found serious data-exposure flaws in the CBSE on-screen marking portal that could let anyone reach student marks, IDs, and contact details, then responsibly reported them to CERT-In and gave a 3-4 week fix window. When the agency stayed silent and left the issues unpatched, he went public to warn schools and parents, after which CERT-In ordered him to stop all further disclosure on national-interest grounds. This matters because it shows how slow official response times can leave millions of student records exposed far longer than they should be. It also highlights that India’s DPDP Act 2023 still lacks a clear safe-harbor for ethical researchers who try to help public institutions. Users and parents should know that ed-tech and board portals need faster, transparent patch timelines, and that pressing institutions for proper vulnerability-disclosure policies is the practical way to reduce the same risk elsewhere.

  • Nisarga Adhikary reported CBSE portal flaws to CERT-In and waited 3-4 weeks before going public.
  • CERT-In issued a stop-disclosure order after the public report, citing national interest.
  • India's DPDP Act 2023 still lacks a statutory safe-harbor for ethical hackers.
  • Ed-tech portals and UPI payment apps face parallel risks if CERT-In delays continue.
  • A national Vulnerability Disclosure Policy with clear timelines is the only long-term fix.

AI-assisted summary, checked by the TamilTech editorial team.

0:00
0:00
🔒 Listen is for subscribers. Subscribe

Key Takeaways

  • Nisarga Adhikary, a cybersecurity researcher, tracked critical flaws in CBSE's on-screen marking_portal and reported them to CERT-In with a 3-4 week remediation window.
  • CERT-In did not resolve or acknowledge the vulnerabilities within that window, pushing Adhikary to issue a public disclosure on his own.
  • CERT-In then directed him to cease all public disclosure, citing national interest and coordinated release protocols.
  • This exposes how India's DPDP Act 2023 lacks a dedicated safe-harbor clause for ethical hackers working with public institutions.
  • Millions of student records in ed-tech portals face prolonged exposure whenever CERT-In response times lag behind vulnerability severity.

What's the news

Nisarga Adhikary discovered serious data-exposure flaws in the CBSE on-screen marking portal during routine security research. The portal handles marks, student IDs, and parent contact information for lakhs of learners across India. Rather than publishing immediately, Adhikary followed the ethical standard and notified CERT-In first. He formally requested that the agency patch the issues within a 3-4 week window. CERT-In took custody of the report but remained silent for weeks, neither fixing server-side misconfigurations nor confirming remediation. Frustrated, Adhikary escalated his findings to public forums to warn schools and parents. Soon after, CERT-In sent him a directive asking him to halt all further public discussion. The notice framed the matter as national-security-sensitive, insisting that only coordinated, pre-approved timelines are permissible for critical educational infrastructure.

Details

Based on the disclosures, the CBSE portal storing marks on a backend PostgreSQL setup had exposed backup dumps and configuration files. Adhikary inferred that student names, roll numbers, exam scores, and admission details could be retrieved without authentication. He did not claim to have exfiltrated data, but noted the attack surface was trivial. CERT-In became the sole interface between the reporter and the institution. However, internal response logs remain opaque. Adhikary stated he tried follow-ups without success. In the Indian context, where ed-tech startups and government boards collect comparable personal data, this delay is a student-rights failure. The portal's exposure could allow unauthorized scraping or targeted attacks on minors. CERT-In's subsequent order to stop further disclosure amplifies opacity rather than closing the vulnerability.

India impact

The fallout directly questions India's cyber-resilience architecture. CBSE is a central authority, yet its incident-response chain proved sluggish. Other education bodies such as state boards, JEE/NEET coaching platforms, and scholarship portals face similar telemetry. When a single vulnerability lingers for a month, the personal data of millions sits in a gray zone. The Digital Personal Data Protection Act 2023 introduced consent and processing principles, but it did not create a statutory safe-harbor for vulnerability researchers. Without clarity, ethical hackers risk legal exposure for trying to protect citizens. This case also signals to private ed-tech firms that patch cycles are negotiable. For platforms processing parent payments via UPI or storing Aadhaar-linked data, India's regulatory stance on disclosure is inconsistent. A researcher today might tolerate a two-week fix window, but a four-week silence from a nodal agency breaks that social contract. In 2026, this incident forces a public conversation on whether CERT-In should disclose its own response SLAs to maintain trust.

Use cases

India urgently needs standardized vulnerability disclosure use cases that balance accountability and national interest. First, public educational domains must maintain a published CERT-In incident-response timeline: 24 hours acknowledgment, 14 days to patch for moderate severity, and immediate public update for critical flaws. Second, a statutory bug-bounty safe-harbor under DPDP rules would shield researchers who act in good faith on Indian servers. Third, CBSE and similar boards should host quarterly penetration-test programs where white-hat teams are invited to pre-assess marks portals. Private ed-tech companies can adopt the same framework via CERT-In coordination cells. 2026 already sees UPI transaction apps, ed-tech wallets, and skill-development platforms storing Indian lifelines; any of them could replicate this CBSE scenario. Finally, schools and parents must treat portal security as a shared duty, asking institutions for breach-response timelines with the same urgency as exam schedules.

Honest take

Both sides have a point, but the balance tilts toward institutional opacity. CERT-In has the mandate to protect critical infrastructure, and a public CBSE portal deserves controls. Yet, when the same agency stays quiet for 3-4 weeks after being handed a fixable flaw, it erodes trust. Adhikary's public move was a warning shot. India has a finite cybersecurity talent pool; if ethical hackers face legal threats for trying to protect citizens, the country loses security coverage. The government should treat this as a pilot for a national Vulnerability Disclosure Policy. Until then, every delayed CERT-In response on a public portal becomes a data bomb. Students pay the price in privacy again and again. That is the real cost of missing SLAs in Indian cyberspace.

FAQs

  • Q: Why did CERT-In ask Nisarga Adhikary to stop talking publicly?

    CERT-In argued that public disclosure of a central educational portal's flaws posed national-security and institutional-reputation risks, and insisted that all release timelines must be coordinated through official channels.

  • Q: What exactly did Nisarga Adhikary find in the CBSE portal?

    He identified publicly accessible PostgreSQL backup files and exposed server configuration paths, which could allow retrieval of student marks, roll numbers, names, and admission records without valid authentication.

  • Q: Is vulnerability disclosure legal in India today?

    It occupies a grey area. While unauthorized access is technically illegal under Indian IT laws, researchers who report in good faith may argue fair-use principles, but there is no explicit statutory safe-harbor for independent hackers under DPDP.

  • Q: Has CERT-In had such a 3-4 week response delay before?

    Public debates around CERT-In response times have surfaced in prior years, but specific delays on education portals have remained less visible. This case puts developmental delays under the spotlight for the first time.

  • Q: Do private ed-tech apps like UPI wallets face similar risks?

    Yes. Any platform storing student payment data or parent contact details, including UPI-linked apps and ed-tech wallets, faces parallel attack surfaces. Without a national VDP, similar delays could leave large user bases exposed.

Get tomorrow’s tech news on WhatsApp

One short update a day, free. Follow the TamilTech channel.

What do you think?

people reacted

Keerthika

TamilTech editorial team · 3,344 articles

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

More from Keerthika

Ask TamilTech on WhatsApp

Tech doubt? Ask in Tamil or English — our WhatsApp assistant answers from TamilTech articles in seconds.

Related stories

Comments (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

Next story PixelLeak: How AI Coding Agents Put 13,000 Internal Screenshots on Public GitHub
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications