Nisarga claims login ID leak by CBSE vendor COEMPT, Sarthak joins in

Nisarga claims login ID leak by CBSE vendor COEMPT, Sarthak joins in

Cybersecurity researcher Nisarga has alleged that a repository linked to CBSE vendor COEMPT exposed plaintext login credentials. The posts have renewed questions over software security practices, though no CBSE system compromise has been established. Earlier reports had raised questions about the company's role in projects linked to the board, prompting discussions among cybersecurity experts over procurement standards and software securityThe technology vendor - COEMPT Edu Teck Pvt Ltd, associated with the Central Board of Secondary Education (CBSE) has come under fresh scrutiny after social media posts alleged that a publicly accessible code repository contained plaintext login credentials, raising concerns over software security practices.In a post on X, cybersecurity researcher Nisarga wrote: "Remember COEMPT, the shady vendor cbse hired?" The post included screenshots purportedly showing a repository linked to COEMPT Edu Teck Pvt Ltd and what appeared to be a file containing email IDs and passwords stored in plaintext. The researcher also commented, "It can't be real."The claims gained further traction after cybersecurity researcher Sarthak Sidhant weighed in on X. Sharing a screenshot related to the alleged exposure, he wrote, "Your favourite company is leaking admin passwords again." His post amplified the discussion among members of the cybersecurity community.COEMPT AND THE ASSOCIATED CONTROVERSIESThe latest allegations come weeks after COEMPT found itself at the centre of the controversy surrounding CBSE's On-Screen Marking (OSM) platform. In June, the Hyderabad-based company rejected allegations of software failures and security lapses, saying reported answer-sheet mix-ups were caused by errors during the physical scanning process rather than flaws in its technology. It also maintained that there had been no security breach and described the reported incidents as isolated operational issues. Cybersecurity experts have long cautioned against storing passwords in plaintext within source code or configuration files, even in development environments. Such practices can expose sensitive information if repositories are made public or accessed by unauthorised users.The screenshots circulating online appear to show login details for different user roles, including administrator and student accounts. However, it could not be established whether these represented real users, test accounts or sample data created for development purposes. - EndsPublished By: Mridusmita DekaPublished On: Jul 31, 2026 11:32 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.