I think this is more of an industry problem than a Microsoft problem. This was a feature added onto an existing service. The old waterfall method of security approvals might have caught this, but for most orgs that has gone the way of the dodo (and probably for the better).
Cosmos DB probably went through security review during the design phase and then again regularly as the code was written and improved. The Jupyter notebook functionality was also likely reviewed by security teams during the design, testing, and implementation phases. But once you're through those approvals most security review is going to be done via automated tooling with only occasional re-reviews and penetration testing at scheduled intervals. Automated testing is great at detecting vulnerabilities that have been discovered in the past, but really not good at detecting new classes of vulnerabilities, hard-to-detect authorization vulnerabilities, or how code integrates with other services.
Once the initial approval and code reviews had been done developers would still be committing code to the service and each line of code is probably not receiving a manual code review. Vulnerabilities like this are hard to detect even with a manual review as the testing team may not have great knowledge of all interconnected services, especially if it's an outside vendor.