ECI portal security flaws reported in July, no action taken yet
A researcher claims that these flaws could expose contact details of election officials and allow attackers to read or alter app data.
A security researcher has claimed that he informed the Election Commission of India and the country's cyber security agency CERT-In in July about vulnerabilities in the Commission's voter service website and the ECINET app. According to him, these could expose the contact details of election officials, and attackers could read the app's data or insert fake information.
The Hindustan Times reported that there was no confirmation of any flaw being fixed for three months. HT sent questions to both entities on October 5. The next day, CERT-In informed the researcher via email that one flaw had been fixed and work was ongoing on the others. It is unclear when the fix occurred. Both entities did not respond to HT's questions.
The researcher, Nisarg Adhikari, had emailed CERT-In on July 8, a copy of which was also sent to the Election Commission's complaint address. He received a response from CERT-In on the evening of October 6.
This issue has emerged amid ongoing concerns regarding ECINET. An investigation by the Indian Express revealed that ECINET restricts access to the voter list database for electoral registration officials and their assistants. This prevents local officials responsible for adding and removing names from making changes. However, the flaws pointed out by the researcher are not directly related to this issue.
The official described a flaw related to a server connected to the voter portal as extremely serious. According to him,
the server was providing the names and mobile numbers of election officials without login, captcha, or any clear limit on the number of requests. He stated that the key necessary to create valid requests was present in the public code of the website. The server did decode the data but did not verify the identity of the requester. It is like a counter that gives information to every person filling out a standard form without asking for identification.
The official checked requests for three role categories of a state and officials. After that, he stopped testing without downloading any dataset. According to him, the server appears to allow information requests based on state, district, constituency, and role. This could make it possible to gather data from across the country.
If these claims are true, a person holding the names, positions, and numbers of officials could contact them as a senior officer or send targeted messages to steal login details. The email also highlighted the risks of SMS misuse and pressuring election staff.

Other findings relate to the ECINET Android app. This includes the cVIGIL app for reporting violations of the model code of conduct, as well as modules for observers, candidates, and facilities.
According to the official,
some data communication checks for the app being connected to the actual ECI server are inactive. This allows someone on a shared network, such as public Wi-Fi, to read or alter the data being sent.
He noted that encryption codes and a persistent access token are present in the app, which can be extracted by anyone downloading the app. Using these, the two active endpoints of cVIGIL provided valid responses without personal login. According to him, this could allow reading data of flying squads and incidents or inserting fake information. In the email dated July 8, he confirmed this on an active system. He wrote that he used non-existent locations in the testing to avoid obtaining real data.
According to the email,
the app stores tokens, phone numbers, and bank details of the observer module without encryption. In this case, a person with access to the device, such as through malware, could take control of the account.
The email does not accuse any data theft or misuse. When asked about the app's version, source, and testing date, the official told HT that he had checked the official ECINET app available on the Google Play Store on July 8, 2026. The Android app has been updated several times in three months; the latest update was on September 30.
HT asked what was found in the cVIGIL testing and whether access to real citizen or incident-related data was possible. The official said he did not recall that flaw, as he handles many security reports and this is an old report. He described the disregard for reports by institutions like ECI as problematic.

Screenshots of the email show that CERT-In's incident desk confirmed that the relevant organization has fixed the “Client-Side Static Response Encryption (Hardcoded AES Key)” flaw. Work is ongoing on the rest. The agency asked the official to verify the improvements.
This is the same flaw that the official considered the least concerning. According to him, the website's server was decoding responses with a key that was present in the public code. Reading the code could expose the data. He described it as an ineffective additional layer of security, as the connection was already encrypted. This also removed the barrier to reading data under a more serious flaw.
ECINET has been in use for a full three months. The Commission launched it on January 22 by adding over 40 apps and web services. The announcement for 2025 stated that it would include apps such as cVIGIL and Suvidha 2.0, which had a combined download of over 5.5 crore, and that cyber security was being tested in trials. On September 26, the Commission ordered a review of ECINET by a committee chaired by the senior deputy election commissioner and an independent expert.
