News

CBSE OnMark Portal Flaws Shift Scrutiny to Vendor Control

Published

on

<p>The CBSE OnMark portal vulnerabilities that the board says it has contained are no longer only a website-security story&period; They test whether India&&num;8217&semi;s biggest school board can prove that outsourced digital evaluation&comma; cloud storage and student data controls are fit for exam records that decide college admissions&period;<&sol;p>&NewLine;<p>On May 31&comma; the Central Board of Secondary Education &lpar;CBSE&comma; India&&num;8217&semi;s national school board under the Ministry of Education&rpar; said an expert team from government arms and the Indian Institutes of Technology &lpar;IITs&comma; public engineering institutes&rpar; had been deployed to secure the OnMark system&comma; according to <a href&equals;'https&colon;&sol;&sol;newsonair&period;gov&period;in&sol;cbse-deploys-cybersecurity-experts-and-iit-teams-to-secure-onmark-portal&sol;' target&equals;'&lowbar;blank' rel&equals;'noopener'>the board&&num;8217&semi;s public cybersecurity statement<&sol;a>&period; The harder test begins after containment&colon; who controlled the system&comma; who audited it&comma; and who can show students that no answer-book record was altered or exposed&period;<&sol;p>&NewLine;<h2>A Containment Notice Leaves a Bigger Burden of Proof<&sol;h2>&NewLine;<p>The board&&num;8217&semi;s language matters&period; It did not say only that a rumour had been answered&comma; as it had done in an earlier phase of the row&period; It said identified vulnerabilities in the OnMark portal of its service provider had been contained&comma; and that other exploitable weaknesses were being ruled out&period;<&sol;p>&NewLine;<p>That wording moves the case from denial to verification&period; A contained flaw can still leave behind questions about access logs&comma; password resets&comma; file downloads&comma; examiner accounts and whether any sensitive student material was available beyond the people who needed it&period;<&sol;p>&NewLine;<ul>&NewLine;<li><strong>May 31&colon;<&sol;strong> the board said identified weaknesses were contained and further checks were under way&period;<&sol;li>&NewLine;<li><strong>February 25&colon;<&sol;strong> Internet Freedom Foundation says researcher Nisarga Adhikary disclosed five vulnerabilities to the Indian Computer Emergency Response Team&period;<&sol;li>&NewLine;<li><strong>Nearly 46 lakh&colon;<&sol;strong> CBSE said its Class X and Class XII board examinations cover that many students across India and 26 countries&period;<&sol;li>&NewLine;<li><strong>116 subjects&colon;<&sol;strong> the board&&num;8217&semi;s OSM FAQ says marking schemes for all subjects were uploaded to the evaluation portal&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;<p>The board can still show that no student was harmed&period; But the evidence has to be technical&comma; dated and public enough for parents&comma; schools and evaluators to understand&period;<&sol;p>&NewLine;<figure class&equals;"wp-block-image aligncenter featured-image" style&equals;"margin&colon;1&period;5em auto&semi;text-align&colon;center&semi;"><img class&equals;"aligncenter" src&equals;"https&colon;&sol;&sol;budgyapp&period;com&sol;wp-content&sol;uploads&sol;2026&sol;06&sol;cbse-onmark-portal-vulnerabilities-raise-student-data-governance-questions&period;webp" alt&equals;"CBSE OnMark portal vulnerabilities raise student data governance questions&period;" style&equals;"width&colon;100&percnt;&semi;max-width&colon;800px&semi;height&colon;auto&semi;border-radius&colon;8px&semi;display&colon;block&semi;margin&colon;0 auto&semi;" &sol;><figcaption style&equals;"text-align&colon;center&semi;font-size&colon;0&period;85em&semi;color&colon;&num;888&semi;margin-top&colon;0&period;5em&semi;">CBSE OnMark portal vulnerabilities raise student data governance questions&period;<&sol;figcaption><&sol;figure>&NewLine;<h2>The Vendor Layer Now Carries the Story<&sol;h2>&NewLine;<p>Public anger has focused on the board because students and schools deal with the board&period; Operationally&comma; the sharper question sits one layer down&period; The controversy concerns a <strong>vendor-owned control plane<&sol;strong> for national exam evaluation&comma; a place where scanned answer books&comma; examiner logins and marks workflows meet&period;<&sol;p>&NewLine;<p>Coempt EduTeck Pvt&period; Ltd&period;&comma; the private company identified in public accounts and by Internet Freedom Foundation &lpar;IFF&comma; an Indian digital rights nonprofit&rpar; as connected to the OnMark platform&comma; has not been placed at the centre of the official public explanation&period; That gap is now costly&period; A system can be procured by a public authority&comma; run by a contractor and hosted through cloud services&comma; but accountability cannot travel in pieces&period;<&sol;p>&NewLine;<p>The board needs to answer a simple chain-of-custody question&period; Who had administrative access at each stage&comma; from scanning to upload to marking to post-result access&comma; and which independent auditor tested those controls before students&&num;8217&semi; records moved through them&quest;<&sol;p>&NewLine;<h2>The OSM Promise Was Administrative Certainty<&sol;h2>&NewLine;<p>CBSE&&num;8217&semi;s case for On-Screen Marking &lpar;OSM&comma; a digital evaluation method in which scanned answer books are marked on a monitor&rpar; was built around fewer manual errors&period; In <a href&equals;'https&colon;&sol;&sol;www&period;cbse&period;gov&period;in&sol;cbsenew&sol;documents&sol;OSM&lowbar;Class&percnt;20XII&lowbar;09022026&period;pdf' target&equals;'&lowbar;blank' rel&equals;'noopener'>the February OSM circular<&sol;a>&comma; the board said Class XII answer books would be evaluated through the system beginning with the current examination cycle&comma; while Class X evaluation would remain physical&period; It listed expected benefits such as automated coordination&comma; faster evaluation&comma; lower transport costs and elimination of totalling errors&period;<&sol;p>&NewLine;<p>CBSE later published <a href&equals;'https&colon;&sol;&sol;www&period;cbse&period;gov&period;in&sol;cbsenew&sol;documents&sol;FAQ-OSM&lowbar;18052026&period;pdf' target&equals;'&lowbar;blank' rel&equals;'noopener'>the board&&num;8217&semi;s OSM FAQ<&sol;a>&comma; which described actual answer books being scanned&comma; quality checks before evaluation&comma; examiner logins&comma; question-wise marks entry and automated totals&period; That is a strong administrative design on paper&period; It also creates several points where a weak access rule&comma; misconfigured storage path or poor logging practice can become a national trust problem&period;<&sol;p>&NewLine;<table>&NewLine;<thead>&NewLine;<tr>&NewLine;<th>Layer<&sol;th>&NewLine;<th>CBSE&&num;8217&semi;s Stated Design<&sol;th>&NewLine;<th>Current Question<&sol;th>&NewLine;<th>Proof Needed<&sol;th>&NewLine;<&sol;tr>&NewLine;<&sol;thead>&NewLine;<tbody>&NewLine;<tr>&NewLine;<td>Scanning<&sol;td>&NewLine;<td>Answer books are scanned without cutting the spine and checked for clarity&period;<&sol;td>&NewLine;<td>Were scans complete&comma; linked to the right barcode and protected from public access&quest;<&sol;td>&NewLine;<td>Sample audit of scans&comma; barcode matches and storage permissions&period;<&sol;td>&NewLine;<&sol;tr>&NewLine;<tr>&NewLine;<td>Evaluator Login<&sol;td>&NewLine;<td>Examiners log in digitally using credentials linked to school data&period;<&sol;td>&NewLine;<td>Could authentication flaws allow account takeover or impersonation&quest;<&sol;td>&NewLine;<td>Authentication audit&comma; password-reset logs and failed-login analysis&period;<&sol;td>&NewLine;<&sol;tr>&NewLine;<tr>&NewLine;<td>Marks Entry<&sol;td>&NewLine;<td>Marks are entered question-wise and totaled by the system&period;<&sol;td>&NewLine;<td>Could a non-authorized user view or alter marks after submission&quest;<&sol;td>&NewLine;<td>Immutable mark-change logs and role-based access review&period;<&sol;td>&NewLine;<&sol;tr>&NewLine;<tr>&NewLine;<td>Post-Result Access<&sol;td>&NewLine;<td>Students can obtain scanned copies through designated channels&period;<&sol;td>&NewLine;<td>Were answer sheets and student records accessible outside approved channels&quest;<&sol;td>&NewLine;<td>Download logs&comma; exposed-object review and student notification criteria&period;<&sol;td>&NewLine;<&sol;tr>&NewLine;<&sol;tbody>&NewLine;<&sol;table>&NewLine;<h2>Data Exposure Allegations Shift the Legal Question<&sol;h2>&NewLine;<p>Adhikary&&num;8217&semi;s latest claims&comma; as described in public posts and reporting&comma; go beyond examiner accounts&period; He alleged that scanned answer sheets and question papers were reachable through a misconfigured cloud storage path&period; He also raised concerns about sensitive student information moving through third-party tools&period; Those claims still need official forensic confirmation&period;<&sol;p>&NewLine;<p>If confirmed&comma; the issue would no longer be only whether marks could be changed&period; It would become a student data case&period; Answer sheets carry handwriting&comma; roll-linked academic performance and sometimes personally identifying metadata&period; For minors and school-leavers&comma; that is a long-lived record&comma; not a disposable exam file&period;<&sol;p>&NewLine;<p>The Digital Personal Data Protection Act &lpar;DPDP Act&comma; India&&num;8217&semi;s privacy law for digital personal data&rpar; is also arriving on a staggered timetable&period; The <a href&equals;'https&colon;&sol;&sol;www&period;indiacode&period;nic&period;in&sol;bitstream&sol;123456789&sol;22037&sol;2&sol;a2023-22&period;pdf' target&equals;'&lowbar;blank' rel&equals;'noopener'>India Code text of the DPDP Act<&sol;a> shows definitions and Data Protection Board provisions already on one clock&comma; while many core data-processing duties under sections 3 to 17 are scheduled for later commencement&period; That timing makes voluntary disclosure and procurement discipline more important&comma; not less&period;<&sol;p>&NewLine;<p>Even before every privacy-duty provision is in force&comma; India&&num;8217&semi;s cyber-incident rules create pressure&period; The <a href&equals;'https&colon;&sol;&sol;www&period;cert-in&period;org&period;in&sol;PDF&sol;FAQs&lowbar;on&lowbar;CyberSecurityDirections&lowbar;May2022&period;pdf' target&equals;'&lowbar;blank' rel&equals;'noopener'>CERT-In incident-reporting FAQ<&sol;a> says severe cyber incidents&comma; data breaches and data leaks should be reported within six hours of being noticed or brought to notice&comma; with more information supplied later if needed&period;<&sol;p>&NewLine;<h2>Responsible Disclosure Became Public Pressure<&sol;h2>&NewLine;<p>The timeline is uncomfortable for any institution that handles high-stakes records&period; IFF said Adhikary disclosed five vulnerabilities to CERT-In on February 25&comma; then published after what he considered an inadequate response&period; IFF&&num;8217&semi;s <a href&equals;'https&colon;&sol;&sol;internetfreedom&period;in&sol;when-the-exam-itself-can-be-hacked-iff-writes-to-the-ministry-of-education-and-cert-in-on-the-cbse-on-screen-marking-disclosure&sol;' target&equals;'&lowbar;blank' rel&equals;'noopener'>digital-rights request for an investigation<&sol;a> asked for a review of the board&&num;8217&semi;s conduct&comma; the vendor contract&comma; remedial steps and public audit disclosure&period;<&sol;p>&NewLine;<p>Public disclosure should never become the preferred way to get critical systems fixed&period; Yet the sequence here shows why researchers lose patience when official channels feel opaque&period; The board thanked ethical hackers after the story had already broken wide&period; That gratitude will matter more if it is followed by a clear safe-reporting process&comma; response deadlines and a published vulnerability-handling policy&period;<&sol;p>&NewLine;<ol>&NewLine;<li>CBSE announced OSM for Class XII evaluation and asked schools to prepare computer labs&comma; connectivity and practice access&period;<&sol;li>&NewLine;<li>A researcher says he reported authentication and access-control flaws to CERT-In before the system finished its public exam cycle&period;<&sol;li>&NewLine;<li>Students later raised complaints about scanned copies&comma; post-result access and the re-evaluation process&period;<&sol;li>&NewLine;<li>The board then said OnMark vulnerabilities had been contained and additional weaknesses were being checked&period;<&sol;li>&NewLine;<&sol;ol>&NewLine;<p>That sequence does not prove marks were changed&period; It does show a public authority trying to modernize faster than its disclosure culture appears to have matured&period;<&sol;p>&NewLine;<h2>The Audit Test CBSE Cannot Skip<&sol;h2>&NewLine;<p>The minimum credible response now is not another assurance that the platform is safe&period; The board needs a <strong>forensic audit trail<&sol;strong> that separates three questions&colon; whether vulnerabilities existed&comma; whether they were exploitable against live data&comma; and whether any unauthorized access or alteration occurred&period;<&sol;p>&NewLine;<p>A useful public audit does not need to reveal fresh attack paths&period; It can publish scope&comma; dates&comma; auditor independence&comma; categories of systems reviewed&comma; number of affected accounts if any&comma; and whether student notifications are required&period; That is how the board can inform without giving a how-to guide to attackers&period;<&sol;p>&NewLine;<ul>&NewLine;<li>Publish the date each identified vulnerability was reported&comma; acknowledged&comma; fixed and retested&period;<&sol;li>&NewLine;<li>Confirm whether live student records&comma; examiner accounts or answer-sheet images were exposed&period;<&sol;li>&NewLine;<li>Release an executive summary from an auditor not previously tied to the deployment&period;<&sol;li>&NewLine;<li>State whether the vendor contract includes breach notice duties&comma; indemnity&comma; audit rights and termination triggers&period;<&sol;li>&NewLine;<li>Create a standing channel for ethical hackers with safe-harbour language and response deadlines&period;<&sol;li>&NewLine;<&sol;ul>&NewLine;<p>There is a policy lesson here beyond one portal&period; Schools are being asked to trust more digital records&comma; more cloud workflows and more automated controls&period; That trust cannot depend on students finding flaws after the system has already handled their futures&period;<&sol;p>&NewLine;<p>If CBSE publishes a dated&comma; independent audit and shows that no student record was altered or wrongly exposed&comma; the OnMark row can become a painful repair job&period; If it stops at containment&comma; every future digital exam system in India will inherit the doubt&period;<&sol;p>&NewLine;

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version