Edit

Bihar Website Security Flaw Put Aadhaar Data at Risk

Bihar Website Security Flaw Put Aadhaar Data at Risk

How the BMVM Portal Vulnerability Was Discovered

A 21-year-old student discovered a serious vulnerability in the Bihar Mahadalit Vikas Mission portal that could have allowed unauthorised access to Aadhaar, PAN, pension, banking, and government login records. The flaw was reported to CERT-In and later fixed.

Bihar Government Website Security Flaw Put Sensitive Data at Risk

New Delhi, July 28, 2026: A Bihar government website security flaw potentially placed a large collection of personal and administrative records at risk before it was reported and fixed.

The vulnerability was discovered by 21-year-old cybersecurity researcher Prashant Kumar on the Bihar Mahadalit Vikas Mission website. The government portal is used to manage beneficiary schemes and other programmes intended for communities across Bihar.

According to the report, the weakness could have provided unauthorised access to information such as Aadhaar numbers, PAN details, telephone numbers, pension records, bank account information, and login credentials belonging to government officials.

Bihar Government Website Security Flaw Linked to Login Page

The vulnerability was reportedly found on the forgotten-password page of the BMVM website. It was linked to an SQL injection weakness, a security issue that can arise when a website fails to safely process information entered by a user.

Prashant Kumar said the portal depended mainly on checks performed on the user’s device instead of carrying out adequate validation on the website’s server.

Client-side checks alone do not provide sufficient protection because they can potentially be modified or bypassed. Server-side validation is needed to ensure that suspicious commands cannot be submitted to a website’s database.

The researcher claimed that the BMVM website's weakness could have allowed a person with basic SQL knowledge to interact with the database without logging in. Depending on the level of access available, such a vulnerability may allow records to be viewed, copied, altered or deleted.

There is no confirmed evidence in the report that an unauthorised person exploited the flaw or downloaded the available information.

What Information Was Potentially at Risk?

The database account connected to the website reportedly had permission to read information from 57 databases hosted on the server.

These databases were said to include recruitment applications containing Aadhaar and PAN details. Some records allegedly contained passwords stored as readable text rather than in a securely protected format.

Applications submitted for driver-training programmes reportedly included names, residential addresses, Aadhaar information and examination marks.

The vulnerability also potentially provided access to the login credentials of around 673 government officials. These accounts reportedly included officials serving as District Magistrates and Block Development Officers.

If valid administrative credentials were obtained, they could potentially be used to enter restricted sections of the portal. However, the report does not establish that such access took place.

Other information reportedly present on the connected databases included records related to pensions, land, employment schemes, voters, and livelihood programmes.

Student Reported BMVM Website Vulnerability to CERT-In

After identifying the problem, Prashant Kumar reported it to the Indian Computer Emergency Response Team, commonly known as CERT-In.

He was reportedly informed that the matter had been forwarded to the technical team responsible for the Bihar government portal. The flaw had been fixed by the time the original report was published.

The disclosure highlights the importance of researchers reporting website vulnerabilities through responsible channels rather than publishing technical instructions that could enable misuse.

It also demonstrates why government portals holding personal information require regular security testing, strong server-side validation, and restricted database permissions.

Incident Raises Questions About Government Portal Security

Government websites frequently store information submitted for welfare schemes, recruitment exercises, licences, and public services. A vulnerability in one application can become particularly serious when the associated account is able to access several databases.

Security practices such as encrypted password storage, limited database permissions, secure input processing, and regular audits can reduce the consequences of a website flaw.

The incident also underlines the need for departments to respond quickly when independent researchers identify weaknesses. A formal vulnerability-disclosure system can help researchers communicate problems safely while giving technical teams an opportunity to fix them.

For beneficiaries, the discovery does not automatically mean their information was stolen or misused. The reported incident concerns a vulnerability that could have enabled unauthorised access, rather than a confirmed public leak of the entire database.

The Bihar government website security flaw was reportedly resolved after being escalated through CERT-In. Further official clarification would be needed to determine whether authorities found evidence of earlier exploitation and how many records were directly accessible through the affected system.

What is your response?

joyful Joyful 0%
cool Cool 0%
thrilled Thrilled 0%
upset Upset 0%
unhappy Unhappy 0%
AD
AD
AD
AD
AD
AD
AD