Security researchers Akshay C.S. and Viral Vaghela identified multiple vulnerabilities in the Indian government’s UMANG platform that exposed personal data across integrated services like EPFO and LPG, according to medianama.com. The flaws involved Universal Account Numbers, LPG booking details, and Aadhaar numbers stored in plaintext, though the Aadhaar module itself was not vulnerable. The Ministry of Electronics and Information Technology (MeitY) has acknowledged the issues and is implementing fixes.
The researchers attributed the vulnerabilities to the platform’s underlying architecture rather than individual services. MeitY told The Hindu that its development and security teams reviewed the findings and are applying corrective and preventive measures, including encrypting plaintext information in the affected APIs. The ministry also examined API transaction logs from the past three months and found consistent transaction volumes while continuing to monitor the platform.
The UMANG platform integrates multiple government services, making the security flaws significant due to the sensitive nature of the data exposed. The researchers criticized the platform’s design, with Viral Vaghela stating, "Almost everything is broken by design." Akshay C.S. also indicated that the fixes implemented so far were insufficient to fully address the vulnerabilities, highlighting ongoing risks to user data.
MeitY confirmed that encryption has been applied to the plaintext data within the concerned APIs and that monitoring of the platform continues. The ministry’s response and remediation efforts are ongoing as of the latest report from The Hindu, cited by medianama.com.