Forced browsing attacks involve directly accessing restricted resources by guessing URLs or parameters. If successful, this means the application failed to properly authorize the request; users can access resources they shouldn't. This reveals authorization flaws, not configuration or session management issues.