Advertisement

Meet the 16-year-old who spotted a JEE Advanced portal flaw before cybercriminals could

A 16-year-old cybersecurity researcher is making headlines after alerting IIT Roorkee to a security flaw in the JEE Advanced 2026 results infrastructure. His discovery prompted a swift response from the institute and has reignited discussions around the cybersecurity of India's high-stakes examination systems.

Advertisement
FP Tech Desk|Jun 05, 2026, 14:08:53 IST

At an age when most students are preparing for competitive exams, 16-year-old Rylen Anil is busy looking for security flaws online.

This week, the young cybersecurity researcher found himself in the spotlight after identifying a vulnerability in the JEE Advanced 2026 results infrastructure that allegedly exposed candidate records and admit-card data. The incident has drawn attention not only to his work but also to the growing cybersecurity challenges facing India's education systems.

Advertisement

A 16-year-old ethical hacker flags and helps fix JEE Advanced cyber flaw

The latest spotlight has fallen on Rylen Anil, a 16-year-old cybersecurity researcher who claimed to have discovered a cloud storage configuration issue affecting the JEE Advanced 2026 results infrastructure.

According to Anil, the publicly accessible cloud storage endpoint did not require authentication, potentially exposing a large volume of candidate-related data. He alleged that nearly 1.8 lakh result records and around 1.87 lakh admit-card PDFs could be accessed, including information such as candidate names, dates of birth and mobile numbers.

techMore from Tech

Instead of exploiting the issue, Anil publicly disclosed the vulnerability and alerted authorities.

His findings prompted a response from IIT Roorkee, the institute that conducted JEE Advanced this year.

"Thank you @DarthKermy72747 for pointing out the configuration issue in the cloud storage device. The same is being plugged on priority," IIT Roorkee said on X. The institute clarified that the stored data was in read-only mode, meaning records could not be altered.

Advertisement

It also praised the teenager's conduct, stating, "We applaud your responsible and ethical behaviour."

The incident occurred just days after the declaration of JEE Advanced 2026 results, in which 56,880 candidates qualified out of more than 1.79 lakh students who appeared for both examination papers.

No data breach

In the most recent X post, he also dismissed the claims around JEE candidates data leak. He said, "While there was a vulnerability, I have not seen evidence supporting claims of a large-scale leak. The issue was promptly reported and swiftly fixed by IIT officials."

IIT Roorkee also took to X, to clear the air around data breach misinformation.

The educational institute said that such claims are "misleading and factually incorrect."

It further explained that there were a certain technical interventions on an expedited basis to assist candidates experiencing difficulties in accessing admit card data and to ensure the smooth functioning of the registration process. "These interventions resulted in a minimal, temporary misconfiguration in a cloud storage component."

However, the affected storage was read only, meaning no data could be edited or deleted.

Another 17-year-old raises questions around CBSE systems

While Anil focused on cybersecurity, another teenager has drawn attention for examining the systems that underpin India's examination processes.

Advertisement

Seventeen-year-old Sarthak Sidhant, a Class 12 student, recently appeared before a Parliamentary Standing Committee reviewing issues linked to CBSE's examination infrastructure and the On-Screen Marking (OSM) system.

According to reports, Sidhant began investigating after receiving what he described as blurred and incomplete scanned copies of his answer sheets. He subsequently reviewed hundreds of publicly available CBSE tender documents and published his findings online.

Among his concerns were alleged changes to procurement conditions involving Hyderabad-based Coempt Edu Teck, the company associated with the OSM platform.

Sidhant claimed that several clauses present in earlier tender documents had either been modified or removed in later versions. These reportedly included provisions related to poor performance, blacklisting and eligibility requirements.

Importantly, he stressed that his concerns were not directed at the OSM system itself.

"I think OSM is a good change, but there should be wide rollouts first and good demo pilots," he said.

CBSE portal reportedly faced 15 lakh hits in two minutes

The concerns raised by both teenagers come against the backdrop of increasing cyber pressure on educational platforms.

Earlier this week, CBSE launched its verification and re-evaluation portal for Class 12 students. Within hours, the board reported an unusually high volume of traffic and what it described as cyber threats targeting the platform.

According to CBSE, the portal received nearly 15 lakh hits within just two minutes at one stage, creating concerns about service disruption.

The board also reported detecting more than one lakh attempts to gain unauthorised access to files, attributing the activity to malicious actors attempting to interfere with operations.

Why these teenage researchers matter

The stories of Rylen Anil and Sarthak Sidhant highlight a growing reality in the digital age: some of the most important discoveries no longer come exclusively from government agencies, cybersecurity firms or large institutions.

As examination systems increasingly move online, vulnerabilities, procurement decisions and system resilience are coming under closer scrutiny. Ethical researchers who identify weaknesses before they can be exploited often become an important first line of defence.

For education authorities, the recent incidents serve as a reminder that securing digital examination infrastructure requires more than technology alone. It also requires openness to feedback, responsible disclosure and constant vigilance from everyone involved, including a new generation of tech-savvy students determined to make the system better.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:Jun 05, 2026, 13:27:36 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next