{"id":9078,"date":"2026-06-01T06:52:27","date_gmt":"2026-05-31T22:52:27","guid":{"rendered":"http:\/\/longzhuplatform.com\/?p=9078"},"modified":"2026-06-01T06:52:27","modified_gmt":"2026-05-31T22:52:27","slug":"password-was-123456-student-alleges-fresh-security-lapses-in-cbse-linked-systems","status":"publish","type":"post","link":"http:\/\/longzhuplatform.com\/?p=9078","title":{"rendered":"&#039;Password was 123456&#039;: Student alleges fresh security lapses in CBSE-linked systems"},"content":{"rendered":"<p><\/p> <div> <p>The controversy surrounding CBSE&#8217;s On-Screen Marking (OSM) system took another turn on Sunday after Sarthak Sidhant, a 17-year-old Class 12 student who recently questioned the board&#8217;s tender process, alleged that security flaws across OnMark-linked portals could put millions of students at risk.<\/p> <p>Sharing a new blog post on X, Sarthak wrote: &#8220;Almost every single OnMark portal built by EduTek is fundamentally insecure, and CBSE is lying to you about the safety of student data. We found default passwords, URL-based RCEs, and raw MD5 hashes. Millions of students are at risk.&#8221;<\/p> <p><strong>Must Read:\u00a0CBSE OSM row: How did a software vendor with an abysmal track record get to decide the future of 98 lakh students?<\/strong><\/p> <div class=\"embedcode\"> <blockquote class=\"twitter-tweet\"> <p dir=\"ltr\" lang=\"en\" xml:lang=\"en\">almost every single OnMark portal built by EduTek is fundamentally insecure, and CBSE is lying to you about the safety of student data.<\/p> <p>we found default passwords, URL-based RCEs, and raw MD5 hashes. millions of students are at risk.<\/p> <p>read the blog here: <a href=\"https:\/\/t.co\/fEvMyIw7pG\">pic.twitter.com\/fEvMyIw7pG<\/a><\/p> <p>\u2014 sidharth (@sidharthify) May 30, 2026<\/p><\/blockquote> <\/div> <p>The latest allegations come just two days after Sarthak&#8217;s analysis of CBSE tender documents shifted attention from complaints about blurred answer sheets and evaluation errors to questions about how the OSM contract was awarded.<\/p> <p>In his latest post, Sarthak claimed that his review of CBSE-linked infrastructure uncovered multiple security weaknesses, including the use of MD5 password hashes on the SARAS portal, CBSE&#8217;s School Affiliation Re-Engineered Automation System.<\/p> <p><strong>Don&#8217;t Miss:\u00a0&#8216;Insanely insecure&#8217;: Ethical hacker alleges CBSE answer sheets, question papers were publicly accessible<\/strong><\/p> <p>According to him, the system stored administrator passwords as raw MD5 hashes, an encryption method widely regarded as obsolete and vulnerable to brute-force attacks.<\/p> <p>&#8220;Fortunately, after discovering this, I immediately emailed them to responsibly disclose the vulnerability,&#8221; he wrote, adding that the issue was subsequently fixed. He noted that SARAS was built by a different vendor and not by EduTek or OnMark.<\/p> <p>Sarthak said the more serious concerns emerged when attention shifted to portals built by EduTek, the company linked to the OSM system.<\/p> <p>He alleged that one administrative portal could be accessed using the password &#8220;123456.&#8221;<\/p> <p>&#8220;He sent me the credentials, and I honestly couldn&#8217;t believe my eyes,&#8221; Sarthak wrote while describing information allegedly shared by 19-year-old ethical hacker Nisarga Adhikary. &#8220;I navigated to the administrative login portal, entered the username he provided, and then typed in the password he had sent me: 123456.&#8221;<\/p> <p>&#8220;To my absolute disbelief, it worked perfectly. I was immediately logged in.&#8221;<\/p> <div class=\"embedcode\"> <blockquote class=\"twitter-tweet\"> <p dir=\"ltr\" lang=\"en\" xml:lang=\"en\">another integral onmark subdomain has been pwn&#8217;ed, this time we managed to get super admin access of the portal. seems like it is tasked with evaluation of exams at various universities. <a href=\"https:\/\/t.co\/JonOLpe5tX\">pic.twitter.com\/JonOLpe5tX<\/a><\/p> <p>\u2014 nisarga (@ni5arga) May 29, 2026<\/p><\/blockquote> <\/div> <p>Sarthak claimed the account provided administrative-level access and argued that weak security practices appeared across multiple OnMark-linked domains.\u00a0<\/p> <p>&#8220;As we kept digging, we realized this wasn&#8217;t just an isolated mistake on a single portal,&#8221; he wrote. &#8220;This catastrophic lack of security was a pattern baked into almost every single OnMark website.&#8221;<\/p> <p>The allegations have surfaced days after Adhikary claimed to have uncovered vulnerabilities in CBSE-linked systems and alleged that examination-related files stored on a cloud server were publicly accessible online.<\/p> <p>CBSE, however, has rejected claims that its actual evaluation platform was compromised.<\/p> <p>Responding earlier this week, the board said a URL cited in social media posts was only a testing site containing sample data and not the portal used for evaluating answer books.<\/p> <p>&#8220;The Portal used for evaluation of answer-books bore a different URL, which has neither been compromised nor does it have the vulnerabilities indicated in the said social media post,&#8221; CBSE said.<\/p> <p>&#8220;The URL: is the testing site only with sample data for internal testing and review purposes. There are no actual evaluation data, marks or other data held on that portal.&#8221;<\/p> <p>The board added that &#8220;no security breaches have come to light on the Portal deployed for the actual evaluation work.&#8221;<\/p> <p>In his earlier blog,\u00a0Sarthak alleged that CBSE modified eligibility and security requirements across successive bidding rounds, changes that he argued may have helped Hyderabad-based Coempt Eduteck secure the contract.<\/p> <p>Sarthak also claimed that Coempt Eduteck was previously known as Globarena Technologies, a company linked to the Telangana Intermediate Examination controversy in 2019.<\/p> <\/div> <p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>CBSE OSM controversy, Sarthak Sidhant, OnMark security, Coempt Eduteck, CBSE cybersecurity, Nisarga Adhikary, CBSE student data, SARAS portal, CBSE answer sheet evaluation, On-Screen Marking system<br \/> #039Password #Student #alleges #fresh #security #lapses #CBSElinked #systems1780267947<\/p> ","protected":false},"excerpt":{"rendered":"<p>The controversy surrounding CBSE&#8217;s On-Screen Marking (OSM) system took another turn on Sunday after Sarthak Sidhant, a 17-year-old Class 12 student who recently questioned the board&#8217;s tender process, alleged that security flaws across OnMark-linked portals could put millions of students at risk. Sharing a new blog post on X, Sarthak wrote: &#8220;Almost every single OnMark [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":9079,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[35151,26714,35149,35025,34767,35147,35152,35030,3204,26487,35027,35150,35146,35148,35026,3449,29422,347],"class_list":["post-9078","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-content-marketing","tag-039password","tag-alleges","tag-cbse-answer-sheet-evaluation","tag-cbse-cybersecurity","tag-cbse-osm-controversy","tag-cbse-student-data","tag-cbselinked","tag-coempt-eduteck","tag-fresh","tag-lapses","tag-nisarga-adhikary","tag-on-screen-marking-system","tag-onmark-security","tag-saras-portal","tag-sarthak-sidhant","tag-security","tag-student","tag-systems"],"acf":[],"_links":{"self":[{"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=\/wp\/v2\/posts\/9078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9078"}],"version-history":[{"count":0,"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=\/wp\/v2\/posts\/9078\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=\/wp\/v2\/media\/9079"}],"wp:attachment":[{"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9078"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/longzhuplatform.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}