Key Takeaways
- Nisarga Adhikary, a cybersecurity researcher, tracked critical flaws in CBSE's on-screen marking_portal and reported them to CERT-In with a 3-4 week remediation window.
- CERT-In did not resolve or acknowledge the vulnerabilities within that window, pushing Adhikary to issue a public disclosure on his own.
- CERT-In then directed him to cease all public disclosure, citing national interest and coordinated release protocols.
- This exposes how India's DPDP Act 2023 lacks a dedicated safe-harbor clause for ethical hackers working with public institutions.
- Millions of student records in ed-tech portals face prolonged exposure whenever CERT-In response times lag behind vulnerability severity.
What's the news
Nisarga Adhikary discovered serious data-exposure flaws in the CBSE on-screen marking portal during routine security research. The portal handles marks, student IDs, and parent contact information for lakhs of learners across India. Rather than publishing immediately, Adhikary followed the ethical standard and notified CERT-In first. He formally requested that the agency patch the issues within a 3-4 week window. CERT-In took custody of the report but remained silent for weeks, neither fixing server-side misconfigurations nor confirming remediation. Frustrated, Adhikary escalated his findings to public forums to warn schools and parents. Soon after, CERT-In sent him a directive asking him to halt all further public discussion. The notice framed the matter as national-security-sensitive, insisting that only coordinated, pre-approved timelines are permissible for critical educational infrastructure.
Details
Based on the disclosures, the CBSE portal storing marks on a backend PostgreSQL setup had exposed backup dumps and configuration files. Adhikary inferred that student names, roll numbers, exam scores, and admission details could be retrieved without authentication. He did not claim to have exfiltrated data, but noted the attack surface was trivial. CERT-In became the sole interface between the reporter and the institution. However, internal response logs remain opaque. Adhikary stated he tried follow-ups without success. In the Indian context, where ed-tech startups and government boards collect comparable personal data, this delay is a student-rights failure. The portal's exposure could allow unauthorized scraping or targeted attacks on minors. CERT-In's subsequent order to stop further disclosure amplifies opacity rather than closing the vulnerability.
India impact
The fallout directly questions India's cyber-resilience architecture. CBSE is a central authority, yet its incident-response chain proved sluggish. Other education bodies such as state boards, JEE/NEET coaching platforms, and scholarship portals face similar telemetry. When a single vulnerability lingers for a month, the personal data of millions sits in a gray zone. The Digital Personal Data Protection Act 2023 introduced consent and processing principles, but it did not create a statutory safe-harbor for vulnerability researchers. Without clarity, ethical hackers risk legal exposure for trying to protect citizens. This case also signals to private ed-tech firms that patch cycles are negotiable. For platforms processing parent payments via UPI or storing Aadhaar-linked data, India's regulatory stance on disclosure is inconsistent. A researcher today might tolerate a two-week fix window, but a four-week silence from a nodal agency breaks that social contract. In 2026, this incident forces a public conversation on whether CERT-In should disclose its own response SLAs to maintain trust.
Use cases
India urgently needs standardized vulnerability disclosure use cases that balance accountability and national interest. First, public educational domains must maintain a published CERT-In incident-response timeline: 24 hours acknowledgment, 14 days to patch for moderate severity, and immediate public update for critical flaws. Second, a statutory bug-bounty safe-harbor under DPDP rules would shield researchers who act in good faith on Indian servers. Third, CBSE and similar boards should host quarterly penetration-test programs where white-hat teams are invited to pre-assess marks portals. Private ed-tech companies can adopt the same framework via CERT-In coordination cells. 2026 already sees UPI transaction apps, ed-tech wallets, and skill-development platforms storing Indian lifelines; any of them could replicate this CBSE scenario. Finally, schools and parents must treat portal security as a shared duty, asking institutions for breach-response timelines with the same urgency as exam schedules.
Honest take
Both sides have a point, but the balance tilts toward institutional opacity. CERT-In has the mandate to protect critical infrastructure, and a public CBSE portal deserves controls. Yet, when the same agency stays quiet for 3-4 weeks after being handed a fixable flaw, it erodes trust. Adhikary's public move was a warning shot. India has a finite cybersecurity talent pool; if ethical hackers face legal threats for trying to protect citizens, the country loses security coverage. The government should treat this as a pilot for a national Vulnerability Disclosure Policy. Until then, every delayed CERT-In response on a public portal becomes a data bomb. Students pay the price in privacy again and again. That is the real cost of missing SLAs in Indian cyberspace.
FAQs
- Q: Why did CERT-In ask Nisarga Adhikary to stop talking publicly?
CERT-In argued that public disclosure of a central educational portal's flaws posed national-security and institutional-reputation risks, and insisted that all release timelines must be coordinated through official channels.
- Q: What exactly did Nisarga Adhikary find in the CBSE portal?
He identified publicly accessible PostgreSQL backup files and exposed server configuration paths, which could allow retrieval of student marks, roll numbers, names, and admission records without valid authentication.
- Q: Is vulnerability disclosure legal in India today?
It occupies a grey area. While unauthorized access is technically illegal under Indian IT laws, researchers who report in good faith may argue fair-use principles, but there is no explicit statutory safe-harbor for independent hackers under DPDP.
- Q: Has CERT-In had such a 3-4 week response delay before?
Public debates around CERT-In response times have surfaced in prior years, but specific delays on education portals have remained less visible. This case puts developmental delays under the spotlight for the first time.
- Q: Do private ed-tech apps like UPI wallets face similar risks?
Yes. Any platform storing student payment data or parent contact details, including UPI-linked apps and ed-tech wallets, faces parallel attack surfaces. Without a national VDP, similar delays could leave large user bases exposed.




Comments (0)
Be the first to comment!