playingUrl for Mr X
with issubscriber: false, user_access: deny, and paid_for: true.video_name + serverhost from the API response are used to construct
the CDN URL above — confirming that the CDN file for this specific movie is
publicly accessible with no authentication.
Centers on secret intelligence agency cases involving five major national threats that were thwarted through covert operations.
Finding: The server sets user_access=deny and
issubscriber=false but still returns playingUrl in the
same response. Subscription is enforced client-side only — any caller with
the expired APK JWT can obtain stream URLs without a subscription.
Munowatch CDN (b-cdn.net) serves content with no auth required
(direct HTTP Range requests succeed with HTTP 206).
{
"id": 64294,
"video_title": "Mr X ",
"description": "Centers on secret intelligence agency cases involving five major national threats that were thwarted through covert operations.",
"video_name": "Mr. X part 1.mp4",
"filehistory": "",
"openload": "0",
"embedurl": "",
"serverhost": "73",
"allow_openload": "0",
"full_video_name": "",
"duration": "01h 11m",
"thumbnail": "https://apposters.b-cdn.net/laba/yo/naki/jMmktpbUMj7844.jpg",
"tfilehistory": "",
"category_id": 5,
"language_id": 1,
"recording_date": "2026-06-01",
"age_id": "18 +",
"location": 1,
"tab_category_id": 5,
"series_code": "53124",
"access": "1",
"paid_for": "1",
"new_movie": "1",
"priority": "No",
"size": "931.62 MB",
"create_date": "2026-06-01 14:09:02",
"schedule_date": "01.06.2026 01:48:57 PM",
"user_id": 1118356,
"vj_id": 9,
"video_status_id": 0,
"network_id": "45.221.10.6",
"user_access": "deny",
"notification": "No",
"secduration": "4300.000000",
"issubscriber": false,
"genre": "Series",
"vjname": "Vj Ice P",
"trailer_playing_url": "",
"episodes": 2,
"episode_state": "NEXT",
"nxt_eps": "EPS 2",
"nxt_eps_id": 64295,
"nxt_eps_title": "Mr X 2",
"nxt_ldur": 0,
"nxt_playing_url": "https://munowatch.co/clips/ELI.mp4",
"playingUrl": "https://munowatch.co/clips/ELI.mp4",
"ldur": 0,
"session_id": "cb99afb5b31411a57538a97393de0e2e",
"device": "web",
"lang_name": "English to Luganda",
"vjrelease": "5 days ago",
"mstatus": false,
"kstatus": "",
"substatus": "EXPIRED"
}