19-Year-Old Ethical Hacker Nisarga Adhikary Bags IIT Kanpur Job After Exposing CBSE Flaws
Nisarga Adhikary, 19, secured a job at IIT Kanpur after ethically exposing major security vulnerabilities in CBSE's online portals.

Top Summary
- What happened: 19-year-old Nisarga Adhikary exposed critical security flaws in CBSE's Online Submission of Marks (OSM) and On-Screen Marking (OSM) systems, then responsibly reported them.
- Why it matters: The discovered vulnerabilities, including master password exposure and OTP bypass, could have severely compromised nationwide student data and examination integrity if exploited maliciously.
- What changes: This incident highlights a growing recognition by premier Indian institutions of non-traditional talent and ethical hacking skills, creating new career pathways beyond conventional degrees.
- Who is affected: CBSE, students nationwide, IIT Kanpur, cybersecurity professionals, and individuals passionate about ethical tech disclosures. Nisarga Adhikary personally benefited with a prestigious job.
From Student to Cyber Expert
A remarkable turn of events has seen 19-year-old Nisarga Adhikary land a prestigious job offer from IIT Kanpur. This opportunity arose after he responsibly flagged critical security vulnerabilities within the Central Board of Secondary Education (CBSE) portals.
Rather than exploiting these glitches, the West Bengal teenager’s ethical disclosure led to a significant professional breakthrough. His story exemplifies the growing value of cyber intelligence and responsible hacking.
Critical Flaws Uncovered
Nisarga, a recent Class 12 graduate from West Bengal, possesses a deep passion for cybersecurity. His sharp technical skills quickly garnered national recognition.
He proactively identified significant security loopholes in CBSE's official portals. Specifically targeted were the 'Online Submission of Marks' (OSM) and 'On-Screen Marking' (OSM) systems.
The vulnerabilities Nisarga uncovered were deemed severe, posing a significant risk to the integrity of examination data. Key among these were:
- Master Password Exposure: A flaw that could grant unauthorized access to sensitive administrative controls within the CBSE system.
- OTP Bypass: A critical vulnerability enabling system logins without the mandatory One-Time Password (OTP) verification process.
These severe flaws, if exploited maliciously, could have jeopardized sensitive student data and the accuracy of examination marks across India.
IIT Kanpur Rewards Ethical Hacking
Demonstrating exemplary ethics, Nisarga chose not to misuse the discovered loopholes. Instead, he acted as a responsible citizen and ethical hacker, reporting the issues directly to the authorities.
Impressed by his cyber intelligence and principled approach, C3iHub, the Technology Innovation Hub of IIT Kanpur, recognized his talent.
The institute has officially appointed Nisarga as an 'OSINT (Open Source Intelligence) and Threat Intelligence Engineer'. This role acknowledges his unique skill set and commitment to cybersecurity.
Shifting Paradigms in Talent Recognition
Nisarga’s journey underscores a significant paradigm shift within premier Indian institutes. It highlights how they are increasingly valuing non-traditional talent and practical skills.
His achievement proves that demonstrable cyber skill and ethical responsibility can open doors to prestigious careers, sometimes even faster than conventional academic degrees.
What to Watch Next
This incident sets a precedent for how ethical hacking and responsible disclosure can be recognized and rewarded by top institutions. It will be interesting to observe if more such opportunities arise for young, skilled individuals without traditional academic backgrounds. Future developments might include new programs or initiatives specifically targeting ethical hackers and cybersecurity talents.
